Law / Frameworks / NIST Privacy Framework / Control-P
NIST Privacy Framework, Control-PCT.PO-P1
Policies, processes, and procedures for authorizing data processing (e.g., organizational decisions, individual consent), revoking authorizations, and maintaining authorizations are established and in place.NIST Privacy Framework, version 1.0, January 2020, CT.PO-P1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 515
- laws
- 210
- places
- 4
- with court rulings behind them
- 39
- not yet in force
- 9
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 3.3 Targeted application scope is specified and documented based on the system’s...
- NIST AI RMFMEASURE 2.10 Privacy risk of the AI system – as identified in the MAP function – is examined and documented.
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-11 Obscene, Degrading, and/or Abusive Content
- MIT mitigations3.3 Access Management
- MIT mitigations3.2 Data Governance
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
169 laws, 160 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 124/2024 On the Protection of Personal Data |
Establish one of the lawful bases Article 7 lists, such as the data subject's consent, contractual necessity, a legal obligation, vital interests, a public task, or a legitimate interest that does not override the data subject's rights, before processing personal data of a person in Albania. Demonstrate that consent was given, present a request for consent separately from other matters in clear and plain language, and let the data subject withdraw consent at any time as easily as it was given. +1 more |
|
| Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11 |
Obtain a lawful basis before processing the personal data of a person in Algeria, whether the processing is automated or manual: express consent, or a legal obligation, a vital interest, a contract with the data subject, a public-interest task, or a legitimate interest. Process a child's personal data only with the consent of their legal representative or the authorisation of the competent judge. |
|
| LQPD, Llei 29/2021 del 28 d'octubre |
Establish a lawful basis under Article 6 before processing personal data of a person in Andorra, and apply the Article 5 principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and security throughout. |
|
| Law on the Protection of Personal Data |
Obtain the data subject's unequivocal, express consent before processing their personal data, or notify the Agência de Protecção de Dados, unless a contract-performance, legal-obligation, vital-interest, public-interest, or legitimate-interest ground applies. Obtain the data subject's consent or the APD's authorisation before processing personal data on their creditworthiness or solvency, unless the information comes from a publicly accessible source, and notify the data subject within sixty days of entering their data in a debtor file. +1 more |
|
| Data Protection Act, 2013 |
Obtain a data subject's consent before processing their personal data, other than sensitive personal data, arising from a commercial transaction, unless a listed alternative ground such as contract performance, a legal obligation, protecting vital interests or the administration of justice applies. |
|
| Ley 25.326, Ley de Protección de los Datos Personales |
Obtain the data subject's free, express, and informed consent before processing their personal data, unless it comes from an unrestricted public-access source, is needed for a State function or legal obligation, is limited to a short listing of name and identifying numbers, arises from a contractual, scientific, or professional relationship, or is financial-entity customer data covered by Ley 21.526. Keep personal data confidential during and after your involvement in processing it, and disclose it to a third party only for a purpose tied to both parties' legitimate interest and with the data subject's prior, revocable, informed consent naming the purpose and the recipient, unless a listed exception applies. +3 more |
|
| Law on Protection of Personal Data, comprehensive regime |
An app that collects, uses, or discloses the personal data of an individual in Armenia must have a lawful basis for processing under Arts. 4-8 of the Law on Protection of Personal Data. |
|
| Datenschutzgesetz (DSG), Data Protection Act |
Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Austria. |
|
| Law on Personal Data, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Azerbaijan, including a facial image or voiceprint, must have a lawful basis under Art. 9.6, most commonly consent for data in an open category or a legislative basis defining the purpose and method of processing, since Azerbaijan's law reaches biometric data under these same ordinary conditions rather than exempting it. |
|
| Personal Data Protection Law, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Bahrain must obtain the Data Subject's consent or rely on a listed alternative lawful basis under the Personal Data Protection Law. |
Show the other 159 laws
| Personal Data Protection Act, 2026, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Bangladesh, including a voiceprint, faceprint, or other biometric identifier, must have a lawful basis before processing, ordinarily the data principal's voluntary, specific, and revocable consent or one of the Act's enumerated legitimate-interest grounds, and must not retain the data beyond what its stated purpose requires. |
|
| Data Protection Act, 2019 |
Before processing personal data, establish a lawful basis and confine processing to the stated purpose. |
|
| Law of the Republic of Belarus On Personal Data Protection |
Establish a lawful basis, generally the personal data subject's consent unless another basis in this Law applies, before processing personal data of a person in Belarus, and limit processing to explicit, pre declared, legitimate purposes, under Article 4. Take consent that is freely given, unambiguous and informed, obtainable in writing, as an electronic document, or in another electronic form, and be ready to prove that it was obtained, under Article 5. |
|
| Act of 30 July 2018 on the Protection of Natural Persons with regard to Personal Data |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Belgium, and treat 13 as the digital-consent age under Act Article 7 for information-society services offered directly to a child. |
|
| Data Protection Act 2021, comprehensive regime from a date not yet set |
Before processing personal data of a person in Belize, establish a lawful basis such as consent, a contract with the data subject, or a legal obligation, and process it fairly, transparently, and only for the specified purpose. Do not process sensitive personal data, including biometric data such as a voiceprint or faceprint, unless a listed condition applies, such as the data subject's consent or a deliberate act by the data subject making the information public. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel) |
Obtain a lawful basis, ordinarily the data subject's consent, before collecting, processing, transmitting, storing, or using their personal data, unless a specific legal exception applies. |
|
| Personal Information Protection Act 2016, application and general principles |
Obtain verifiable consent from a parent or guardian before relying on consent to use a child's personal information in a service targeted at children or known to be used by a child. |
|
| Information, Communications and Media Act of Bhutan 2018, data protection and privacy duties |
An app that collects, uses, or discloses the personal data of an individual in Bhutan, including a voiceprint, faceprint, or other biometric identifier, must obtain the subject's express written permission before collecting it and must not disclose it to a third party without authorization. An ICT or media service provider or vendor must additionally publish a privacy policy, limit collection and use to what is reasonably appropriate, store and use data only for its intended purpose, and remain responsible for data it transfers to a third party. |
|
| Reglamento para el Desarrollo de TIC, Tratamiento de los Datos Personales |
Obtain a person's prior knowledge and express consent before collecting, processing, blocking, cancelling, transferring, consulting, or interconnecting their personal data. Do not use, communicate, or transfer personal data to a third party without the data subject's consent or a competent court's written order. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina |
Establish a lawful basis under Article 8 before processing personal data of a person in Bosnia and Herzegovina, and appoint a Data Protection Officer under Articles 39 to 41 wherever the processing meets the threshold the Act sets, such as processing carried out by a public authority or large-scale monitoring or special-category processing. |
|
| Data Protection Act, 2024 (Act No. 18 of 2024) |
Obtain a lawful basis before processing personal data of a person in Botswana, or of a person elsewhere if the processing is by a controller or processor established in Botswana. Be able to demonstrate that a data subject has consented to processing based on consent, and let the data subject withdraw that consent at any time. |
|
| Lei Geral de Proteção de Dados Pessoais (LGPD) |
Establish a lawful basis under article 7 before processing personal data, including data the person has made public. Take consent only when it is provided in writing or by another means demonstrating the data subject's free will, in a clause set apart from the other contract terms, and be ready to prove it meets these requirements. |
|
| Personal Data Protection Order 2025, comprehensive regime |
Brunei's Personal Data Protection Order 2025 has been in effect since for Parts 3 to 9, section 42, and Schedules 1 to 5, the commencement date Government Gazette No. S 11/2025 directly confirms. An app that collects, uses, or discloses the personal data of a person in Brunei, including a voiceprint, faceprint, or other biometric identifier, since the Order draws no sensitive-category distinction, must obtain the individual's consent or rely on a Schedule 1, 2, or 3 consent-free basis before processing. |
|
| Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Bulgaria; the Act's own text is not confirmed, and any Bulgarian-specific addition to that basis is unverified. |
|
| Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel |
Obtain the data subject's prior consent before processing their personal data, unless a specific legal exception applies, such as performing a contract, complying with a legal obligation, protecting a vital interest, or a public interest ground. |
|
| Law No. 133/V/2001 on the Protection of Personal Data |
Process personal data only where the data subject has unambiguously consented or where processing is necessary for a contract, a legal obligation, the data subject's vital interests, a public interest task, or your or a third party's legitimate interest that does not override the data subject's rights. |
|
| Draft Law on Personal Data Protection, final draft proposed |
If enacted as drafted, a data controller or processor would need one of six legal bases, including the data subject's consent, before processing personal data, and would need a parent or guardian's verified consent before processing the personal data of a data subject under the age of 16. |
|
| Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set |
Rely on a lawful basis, consent, a legal obligation, a public-interest mission, or health protection, before processing personal data, and where consent is the basis, make it free, informed, specific, unequivocal, and express. Obtain parental or legal-representative consent before processing the personal data of a person under 18. +1 more |
|
| Bill C-36, Protecting Privacy and Consumer Data Act proposed |
Not yet in force. If enacted as proposed, would require organizations to be transparent about their use of automated decision making for significant decisions about individuals, set higher standards for handling children's information, and obtain meaningful consent supported by plain-language explanations. |
|
| Personal Information Protection and Electronic Documents Act (PIPEDA) |
Obtain knowing, meaningful consent before collecting, using or disclosing personal information, and limit collection to what a reasonable person would consider appropriate for the stated purpose. |
|
| Data Protection Act 2021 Revision, application, principles and data subject rights |
Have a lawful basis for collecting and processing personal data, and hold it only for specified purposes. |
|
| Loi n° 24.001 portant protection des données à caractère personnel |
Have a lawful basis, such as a contract's performance, a legal obligation, a legitimate interest that does not override the data subject's rights, the data subject's freely given and revocable consent, a vital interest, or a public interest mission, before processing someone's personal data. |
|
| Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation) |
Process personal data only with the data subject's consent, or, absent consent, only when indispensable to a legal obligation, a public-interest mission, a contract with the data subject, or the data subject's vital interest. |
|
| Ley 19.628, sobre Protección de la Vida Privada |
Obtain a lawful basis before processing personal data of a person in Chile through a registry or data bank, whether the processor is a public body or a private party, per Ley 19.628 Article 1. |
|
| Ley 21.719, Regula la Protección y el Tratamiento de los Datos Personales from , in 2 months |
From , obtain a lawful basis before processing personal data of a person in Chile; this obligation does not yet bind as of this writing. |
|
| Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases |
Establish one of PIPL's enumerated lawful bases, most commonly informed consent, before collecting or processing personal information of a person in China. |
|
| Ley 1581 de 2012, General Personal Data Protection |
Obtain the data subject's prior, explicit and informed authorization before collecting or processing their personal data, unless a statutory exception applies. Keep proof of the data subject's authorization, tell them at authorization the purpose of the processing, keep their personal data updated and accurate, secure it against unauthorized alteration, loss, consultation, use or access, and correct it once it is shown to be incorrect. |
|
| Superintendencia Circular on AI and Personal Data |
Before collecting personal data from the internet to develop, train, test or deploy an artificial intelligence system, obtain the data subject's prior, express and informed authorization; a datum being accessible online does not make it a public datum exempt from that requirement. |
|
| SB 21-190, Colorado Privacy Act (CPA) |
Obtain the consumer's affirmative opt-in consent before processing sensitive data, including biometric data used for identification, or before resuming processing for targeted advertising or sale after a consumer opts out. |
|
| Protección de la Persona frente al Tratamiento de sus Datos Personales |
Before collecting a person's personal data, inform them of the purpose of collection and obtain their express, written consent, unless the data are publicly accessible or a law or judicial order compels disclosure. Do not process data revealing racial or ethnic origin, political opinions, religious convictions, health, or sexual orientation without the data subject's consent or another narrow statutory ground. |
|
| Act on the Implementation of the General Data Protection Regulation |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Croatia, following the Act's institutional and procedural rules. |
|
| Ley 149/2022, De Protección de Datos Personales, general regime |
Obtain the data subject's express, unambiguous, free and informed consent before collecting or processing sensitive data (sex, gender identity, sexual orientation, ethnic origin, health, disability, genetic information, religious belief, political affiliation, or criminal record), absent a statutory exception. |
|
| Law 125(I)/2018, Cyprus GDPR Supplement |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Cyprus, including data collected by crawling. |
|
| Act on Personal Data Processing |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in the Czech Republic; Act 110/2019 supplies the UOOU's procedural powers rather than a substantive addition to that basis. |
|
| Law No. 2013-450 on the Protection of Personal Data |
Have a lawful basis, such as the person's express consent, before collecting, transmitting, storing or using anyone's personal data, whether the processing is automated or not. Do not send unsolicited electronic direct-marketing messages using a person's personal data without their consent. +1 more |
|
| Digital Code, Title III: Personal Data Protection |
Obtain the data subject's consent before processing their personal data, unless the processing is necessary to perform a legal obligation. |
|
| Danish Data Protection Act (Databeskyttelsesloven) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Denmark, including data collected by crawling. |
|
| Digital Code, Book I: Personal Data Protection and CNDP |
Obtain a lawful basis, most often the data subject's express, unambiguous, free, specific and informed consent, before processing their personal data. |
|
| Ley No. 172-13 sobre Protección Integral de los Datos Personales |
Obtain the data subject's free, express, and conscious consent before processing or transferring their personal data, unless the law lists an exception. |
|
| LOPDP, comprehensive personal-data protection regime |
Do not process personal data without a lawful basis under the Act, and obtain explicit consent before processing a sensitive category of data unless another enumerated ground applies. |
|
| Law No. 151 of 2020 Promulgating the Personal Data Protection Law |
Obtain the data subject's explicit consent before processing their personal data unless another lawful ground applies, such as performing a contract, complying with a legal obligation, or acting under a judicial order. |
|
| Ley para la Protección de Datos Personales |
Obtain a person's express, informed, free, specific and individualized consent, or another lawful basis this Law recognizes such as contractual necessity, a legal obligation, vital interests, or a legitimate interest that does not override the data subject's rights, before processing their personal data, unless this Law excuses consent for the specific processing. Let a data subject revoke their consent at any time without retroactive effect, and act on a revocation within five business days of the request. +1 more |
|
| Ley de Protección de Datos Personales |
Obtain clear, unequivocal consent before processing a person's personal data, and express written consent before processing a sensitive category (race, tribe or ethnicity, health, sexual life, religious, political or union creed). |
|
| Civil Code of the State of Eritrea, Personality Rights (Image and Correspondence) from a date not yet set |
Do not exhibit, reproduce, or offer for sale a person's photograph or image without that person's consent, unless the image concerns a fact, event, or ceremony of public interest or one that took place in public, or the person's notoriety, public office, or the requirements of justice, police, or a scientific, cultural, or didactic interest justifies the use. Do not divulge the contents of a confidential letter, electronic message, or other private communication addressed to another person without the consent of its author. |
|
| Personal Data Protection Act (Isikuandmete kaitse seadus) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Estonia, including data collected by crawling. |
|
| Data Protection Act, 2022 (Act No. 5 of 2022) |
Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, compliance with a legal obligation, or another listed ground, before processing personal information of an identifiable individual, whether by automated or non-automated means. |
|
| Personal Data Protection Proclamation |
Have a lawful basis for processing personal data before collecting, storing, or otherwise processing it, whether by automated means or in a filing system. Take consent only where it is free, informed, specific and clear and requires an active action from the data subject, request it separately from other terms rather than bundled with them, let the data subject withdraw it at any time, and be able to prove it was given. |
|
| General Data Protection Regulation (GDPR), Comprehensive Regime |
Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU. |
|
| Data Protection Act (Tietosuojalaki) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Finland, including data collected by crawling. |
|
| Loi Informatique et Libertés, GDPR-Aligned Comprehensive Regime (Data Processing, Data Files and Individual Liberties Act) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in France, and follow Loi 78-17 Article 6's cross-reference to GDPR Article 9 for any special-category data. |
|
| Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023 |
Have a lawful basis for processing, such as the data subject's consent, a legal obligation, a public-service mission, contract performance, or a legitimate interest that does not override the data subject's own rights and freedoms. Where you rely on consent, be able to demonstrate it was given and present the request clearly and separately from other terms; never treat acceptance of general terms of use or a pre-checked box as consent, and in an electronic transaction take it through an unambiguous act such as a checkbox. +1 more |
|
| Personal Data Protection and Privacy Act, 2025 from a date not yet set |
Establish one of the Act's seven lawful bases before processing personal data, whether you are established in The Gambia or process the data of individuals in the country from outside it. |
|
| Law on Personal Data Protection, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Georgia must establish a lawful basis for the processing under Art. 5 of the Law on Personal Data Protection. |
|
| Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act |
Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Germany. Where you process employee data, including biometric data for workplace access or time and attendance, satisfy BDSG Section 26(3)'s stricter conditions rather than relying on employee consent alone. |
|
| Data Protection Act |
Have a lawful basis for processing personal data, and register with the Data Protection Commission before processing begins. Do not require a person to supply or produce a particular record, including a health record, as a condition of providing them goods, facilities, or services, unless the requirement is authorised by law or is in the public interest. |
|
| Law 4624/2019, Greek GDPR Implementation Law (Nomos 4624/2019, N. 4624/2019) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Greece, including data collected by crawling. Ground employee consent to data processing in Greece on more than the ordinary GDPR consent standard, since Law 4624/2019 narrows employee consent to exceptional cases given the dependence inherent in an employment relationship, per secondary commentary. |
|
| Data Protection Act, No. 1 of 2023 from a date not yet set |
Establish a lawful basis, ordinarily the data subject's consent, before processing personal data about them, or rely on one of the Act's specific alternative grounds such as contractual necessity, a legal obligation, or a statutory or government function. Do not disclose personal data for a new purpose or to a new class of recipient without the data subject's consent, unless the disclosure prevents or detects crime, is authorised by an enactment or court order, or the Minister deems it justified as being in the public interest. |
|
| Ley de Acceso a la Información Pública, Decreto 57-2008 (personal-data provisions) |
Do not disseminate, distribute, or commercialize personal data held in an information system without the data subject's express written consent. Never commercialize sensitive personal data (racial or ethnic origin, political ideology, religious belief, health, sexual life, or similarly intimate data) by any means. +1 more |
|
| Infotörvény (Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Hungary; the Infotorveny supplements the GDPR with mainly procedural rules rather than a substantive addition to that basis. |
|
| Act No. 90/2018 on Data Protection and the Processing of Personal Data |
Establish a lawful basis under Act No. 90/2018 Article 8 (mirroring GDPR Article 6) before processing personal data of a person in Iceland, including data collected by crawling. |
|
| Digital Personal Data Protection Act, 2023, comprehensive regime and lawful basis from , in 7 months |
India's Digital Personal Data Protection Act has not yet begun to bind app developers as of the date shown; its lawful-basis and consent duties are scheduled to commence . Once in force, an app that collects, uses, or discloses the personal data of an individual in India, including a voiceprint, faceprint, or other biometric identifier, which the Act treats as ordinary personal data since it has no separate sensitive-category tier, will need a lawful basis under section 4, ordinarily the data principal's free, specific, informed, and unambiguous consent under section 6, or one of section 7's enumerated legitimate uses. |
|
| Law on Personal Data Protection, comprehensive regime |
An app that collects, uses, or discloses the personal data of an individual in Indonesia must establish a lawful basis under Article 20, most commonly consent, though the procedural detail for several related duties awaits implementing regulations that had not yet issued as of the date shown. |
|
| Data Protection Act 2018 |
Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Ireland. |
|
| DPC Guidance: AI, Large Language Models and Data Protection |
Establish a lawful basis before collecting or otherwise using personal data, including publicly accessible personal data, to train an AI model on people in Ireland, and account for the purpose the person originally made that data public for, not only whether it was public. |
|
| Codice Privacy (Personal Data Protection Code), as Amended for GDPR Alignment |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Italy, following the Codice Privacy's institutional and procedural rules. |
|
| Data Protection Act, 2020, registration, lawful basis and standards for processing |
Have at least one condition under section 23 for every processing operation, such as the data subject's consent, the performance of a contract, a legal obligation, or a legitimate interest that is not outweighed by the data subject's rights and freedoms. |
|
| Personal Data Protection Law, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Jordan must obtain consent or rely on one of the Law's enumerated alternative bases, must confine retention to the processing purpose unless legislation specifies otherwise, and must appoint a data-protection lead if it processes Sensitive Personal Data or transfers personal data to a database outside Jordan. |
|
| Law on Personal Data and Their Protection, comprehensive regime and lawful bases |
An app that collects, uses, or discloses the personal data of individuals in Kazakhstan must obtain the subject's consent, or rely on one of the Law's limited consent-free grounds, before processing, and must confine that processing to the stated purpose of collection. |
|
| Data Protection Act, 2019 |
Obtain consent from a child's parent or guardian, verified through an age-verification mechanism, before processing that child's personal data. |
|
| Data Protection Act 2025 from a date not yet set |
On commencement, process personal data only on one of the Act's lawful bases, such as consent, contract necessity, legal obligation, or legitimate interests, and only for a purpose that is explicit and not prohibited by law. |
|
| Law No. 06/L-082 on Protection of Personal Data |
Establish a lawful basis under Article 5 before processing personal data of a person in Kosovo, and apply the Article 4 principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability throughout. Use personal data collected from public sources for direct marketing only as Article 73 allows, limited to name, address, telephone number and email address unless the data subject has separately consented, and obtain written consent before using sensitive personal data for marketing. |
|
| CITRA Data Privacy Protection Regulation from a date not yet set |
An app that is a CITRA-licensed telecommunications or information-technology service provider in Kuwait must, per secondary legal-commentary sources not yet confirmed at primary source, obtain a customer's explicit consent (or a guardian's, for a minor under 18) before collecting or processing personal data, a duty that reaches a voiceprint or faceprint like any other identifying data, since the reported consent requirement carries no category-specific qualification; this is an inference from secondary commentary, not an independently confirmed reading of the regulation's own biometric-data treatment. Kuwait has no general cross-sector personal-data statute, so an app outside CITRA's licensed scope is not currently bound by a dedicated privacy law of this kind. |
|
| Personal Data Processing Law (Fizisko personu datu apstrādes likums) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Latvia, including data collected by crawling. |
|
| Data Protection Act, 2011 (Act No. 5 of 2012) |
Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, compliance with a legal obligation, or another listed ground, before processing personal information of an identifiable individual, whether by automated or non-automated means. |
|
| Telecommunications Act of 2007, Protection of Personal Information (§§ 51-52) |
Collect, use, maintain, or disclose a telecommunications customer's information or communications only as permitted or required by law, or with that customer's consent. |
|
| Law No. 6 of 2022, protection of personal data collected in electronic transactions |
Before collecting personal data for issuing, maintaining, or facilitating an authentication certificate, obtain the person's explicit consent, and do not use it for a different purpose without a further explicit consent. Do not collect, disclose, provide, or process personal data without the data subject's consent unless it is necessary to prevent or detect a crime under an official request from investigative bodies, required or permitted by law or a court decision, needed for a tax assessment or collection, or needed to protect the person's vital urgent interest. +1 more |
|
| Datenschutzgesetz (DSG) |
Establish a lawful basis under the DSG, mirroring GDPR Article 6, before processing personal data of a person in Liechtenstein, including data collected by crawling. |
|
| Law on Legal Protection of Personal Data |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Lithuania, including data collected by crawling. |
|
| Act of 1 August 2018 on the Organisation of the CNPD and the General Data Protection Framework |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Luxembourg, including data collected by crawling. |
|
| Law No. 2014-038, protection of personal data |
Have the data subject's consent, or another of the five lawful grounds in article 17, before processing personal data. Process data on a subcontractor's behalf only on the controller's instructions, and use only a subcontractor that offers sufficient guarantees to implement the required security measures. |
|
| Broadband internet access service, customer personal information privacy from a date not yet set |
Obtain a Maine broadband customer's express, affirmative, opt-in consent before using, disclosing, selling, or permitting access to their customer personal information, and let them revoke that consent at any time. Do not refuse service, or charge a penalty or offer a discount, based on a customer's consent decision under this statute. |
|
| Electronic Transactions and Cyber Security Act, 2016, personal data processing and security duties (Part VII) |
Have a lawful basis before processing personal data: the data subject's unambiguous consent, contractual necessity, compliance with a legal obligation, protecting the data subject's vital interests, a public interest or official task, or your own legitimate interests where they do not override the data subject's rights and freedoms. |
|
| Personal Data Protection Act, comprehensive regime and lawful bases |
An app that collects, uses, or discloses the personal data of an individual in Malaysia must obtain consent, subject to the contract, legal-obligation, or vital-interest exceptions, and processing sensitive personal data needs the data subject's explicit consent under the Act's stricter standard. |
|
| Personal Data Protection Bill, pending before the People's Majlis proposed |
If enacted as drafted, a Controller or Processor would need a lawful basis before processing personal data, would have to collect it only for specific, explicit and legitimate purposes declared before collection, and would not be able to process it further in a way incompatible with those purposes. |
|
| Data Protection Act, Chapter 586 of the Laws of Malta |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Malta, including data collected by crawling. |
|
| Data Protection Act 2017, establishment and lawful processing |
Process personal data lawfully, fairly and transparently, only for an explicit and legitimate purpose that fits one of the Act's listed lawful-processing grounds. Obtain the consent of a child's parent or guardian, verified with reasonable effort, before processing the personal data of a child below 16. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) |
Obtain the data subject's consent, express or tacit, before processing their personal data, unless a listed statutory exception applies, and treat consent for financial or patrimonial data as requiring express consent. |
|
| Law No. 195/2024 on Personal Data Protection |
Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Moldova. Take consent only on the conditions article 7 sets, and be able to demonstrate the data subject gave it. |
|
| Loi sur la Protection des Données Personnelles |
Establish one of the lawful bases Article 5 lists, such as consent, contract necessity, a legal obligation, vital interests, an important public interest ground, or legitimate interest, before processing personal data of a person in Monaco. Take consent only as a free, specific, informed and unambiguous act, present a bundled consent request separately from other terms, and do not make consent a condition of a good or service unless the processing is indispensable to providing it. |
|
| Law on Personal Data Protection from a date not yet set |
Establish a lawful basis, such as the data subject's prior consent or one of the grounds listed in Article 10, before processing personal data of a person in Montenegro. |
|
| Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data |
Obtain the data subject's unambiguous consent before processing their personal data, unless a legal obligation, contract performance, vital interest, public interest mission, or legitimate interest ground applies. |
|
| Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications |
As a licensed communications service provider, do not disclose information concerning a subscriber without the subscriber's written consent, unless the Act or another written law requires or authorises the disclosure. Take reasonable steps to maintain the confidentiality of a subscriber's communications, and do not intercept, monitor, alter, or modify their content except as permitted or required by law. +2 more |
|
| Privacy Act, 2075, general privacy and collection regime |
An app that collects, uses, or discloses the personal information of an individual in Nepal, including a voiceprint, faceprint, or other biometric identifier, must have the person's consent or fall within a statutory exception before collecting it, and a body corporate must limit use to its stated purpose and obtain consent before using the information for another purpose. |
|
| Uitvoeringswet Algemene verordening gegevensbescherming (UAVG), GDPR Implementation Act |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in the Netherlands, following the UAVG's institutional and procedural rules and Chapter 3-4 national derogations. |
|
| Privacy Act 2020, Information Privacy Principles and Extraterritorial Reach |
Do not collect personal information unless it is for a lawful purpose connected with a function or activity of your organisation and the collection is necessary for that purpose. |
|
| Ley No. 787, Ley de Protección de Datos Personales |
Before processing personal data, obtain the data subject's consent, unless a listed exception applies. Assign or transfer personal data domestically only for a purpose directly related to your legitimate interest and that of the recipient, and only with the data subject's prior, informed, and revocable consent, unless a listed exception applies. |
|
| Loi n° 2022-59, protection des données à caractère personnel |
Obtain the data subject's express prior consent before processing their personal data, unless the processing is necessary for a legal obligation, a public-interest or official mission, performance of a contract, or safeguarding the data subject's own vital interests or fundamental rights. |
|
| Nigeria Data Protection Act, 2023 (NDPA), general data protection duties |
Process personal data on one of the lawful bases section 25 recognises, and hold to the section 24 principles of fairness, lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, confidentiality, integrity and availability. Take consent for cookies and other tracking tools freely, informed and specific, display a conspicuous cookie banner at the first part of the page, and let a data subject reject every cookie other than the necessary ones that carry security, network stability and accessibility. |
|
| Law on Personal Data Protection (LPDP) |
Get the Agency's prior approval before any systematic and extensive processing of a citizen's national identification number, and otherwise process it only with the data subject's prior consent or another case a law states. Process personal data for direct marketing, including related profiling, only after the data subject has given explicit consent. |
|
| Law on Personal Data Protection (LPDP), video surveillance |
Obtain the written consent of at least 70% of the owners or tenants of a single-unit or multi-unit residential building before introducing video surveillance there, and never transmit its recordings over cable television, the internet or another electronic means, or record the entrances to other individual apartments. |
|
| Personal Data Act (personopplysningsloven) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Norway, including data collected by crawling. Ground the processing of a Norwegian national identity number (fodselsnummer) or other unique identifier on a legitimate need for secure identification, under Personal Data Act Section 12. |
|
| Oregon Consumer Privacy Act (OCPA), general applicability and controller duties |
Do not sell precise geolocation data or process a known Oregon minor's (under-16) data for targeted advertising, sale, or profiling; both are prohibited outright as of . |
|
| Ley 81 de 2019, Sobre Protección de Datos Personales |
Have a lawful basis, such as consent, contractual necessity or a legal obligation, before processing a person's personal data, and use it only for the purpose for which it was collected. |
|
| Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months |
Establish a valid legal basis, such as the data subject's consent or a contract, before processing any personal data, and make sure any consent obtained is prior, free, informed and unambiguous. Obtain the consent of a child or adolescent only on the terms article 7 sets, and rely on legitimate interest only where article 8 allows. |
|
| Ley 29733, Ley de Protección de Datos Personales |
Obtain a person's prior, informed, express, and unequivocal consent before processing their personal data, unless a law authorizes the processing without it, and let them revoke that consent at any time under the same requirements that applied when they gave it. |
|
| Data Privacy Act of 2012, comprehensive regime and lawful processing criteria |
An app that processes the personal information of an individual in the Philippines must satisfy one of the Act's lawful-processing criteria, with a stricter, separate standard for sensitive personal information, even though the Act's own sensitive-category list does not name biometric data specifically; a faceprint or voiceprint is still personal information subject to the Act's general processing criteria. |
|
| Act on the Protection of Personal Data of 10 May 2018 |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Poland; the Act adds no Polish derogation to the Article 6 list. |
|
| Lei n.o 58/2019, Portuguese GDPR Implementation Law (Lei de Execução do RGPD) |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Portugal, including data collected by crawling. |
|
| Personal Data Privacy Protection Law, comprehensive regime |
An app that collects, uses, or discloses the personal data of an individual in Qatar, including a voiceprint, faceprint, or other biometric identifier, must have a lawful, consent-and-purpose-based basis for processing under the PDPPL; Qatar's special-nature-data list does not name biometric data as its own heightened category, but ordinary personal data duties still apply to it. |
|
| Québec | Act respecting the protection of personal information in the private sector, comprehensive regime |
Obtain clear, free and informed consent requested for each specific purpose before using or communicating personal information for a purpose other than the one for which it was collected, and obtain express consent where the information is sensitive. |
| Law No. 29-2019 on the Protection of Personal Data |
Obtain the data subject's consent before processing their personal data, unless a legal obligation, public-interest mission, vital-interest, or another statutory ground applies. |
|
| Law No. 190/2018 on Measures for the Implementation of Regulation (EU) 2016/679 |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Romania; the Act's own text is not confirmed, and any Romanian-specific addition to that basis is unverified. |
|
| Federal Law No. 152-FZ "On Personal Data" |
Establish one of the six Article 6 lawful bases, consent, contract performance, legal obligation, vital interests, legitimate interests, or the journalism/science/literature/art exception, before processing personal data of a person in Russia. |
|
| Law relating to the Protection of Personal Data and Privacy |
Have a lawful basis under this Law, such as the data subject's consent or one of the other seven grounds article 46 lists, before processing personal data. Where consent is the basis for processing, obtain it only after the data subject is informed of the consequences of consenting, and let the data subject withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal. |
|
| Data Protection Act, 2018 from a date not yet set |
Obtain a data subject's consent before processing their personal data other than sensitive personal data, unless a listed exception applies. Do not disclose personal data for a new purpose without the data subject's consent, except where crime prevention or detection, legal authorisation, a reasonable belief in a right or in the data subject's consent, or the public interest applies. |
|
| Data Protection Act |
Obtain a person's express consent before processing their personal data, unless a specific ground applies such as performing a contract with them, complying with a legal obligation, or a legitimate interest that does not override their privacy rights, and let them object to processing done on public interest or legitimate interest grounds and revoke consent at any time. |
|
| Telecommunications Act 2005, confidentiality and protection of customer personal information |
Do not disclose information concerning a telecommunications customer without the customer's written consent, unless disclosure is required or permitted by the Regulator or by law. Take all reasonable steps to keep customer communications confidential, and do not intercept, monitor, alter, or modify their content except as the Act permits. |
|
| San Marino Law No. 171 on the Protection of Natural Persons |
Establish a lawful basis before processing personal data of a person in San Marino under Law 171/2018. Take consent only where you can demonstrate the data subject gave it, and for an information society service offered to a child, only on the terms article 7 sets. |
|
| Lei n.º 03/2016, Protecção de Dados Pessoais |
Obtain the data holder's unequivocal authorization before processing their personal data, or rely on one of the Law's specific grounds: performing a contract with them, a legal obligation you face, protecting their vital interests, a public-interest mission, or your own legitimate interest weighed against their rights. |
|
| Personal Data Protection Law, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Saudi Arabia must establish a lawful basis under the Personal Data Protection Law, most commonly the Data Subject's consent, following the consent mechanics set out in the Implementing Regulations. |
|
| Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act) |
Have a lawful basis, ordinarily the person's consent, before collecting, processing, transmitting, storing, or using their personal data. |
|
| Law on Personal Data Protection |
Have one of the lawful grounds Article 12 lists, such as consent, contract necessity, legal obligation, vital interest, public interest, or legitimate interest, before processing personal data of a person in Serbia. Take consent only where you can demonstrate it was given, present a bundled consent request separately from other matters in plain, simple language, and let the person withdraw consent at any time as easily as they gave it. |
|
| Data Protection Act, 2023, application and processing principles |
Have a lawful basis for processing personal data, such as informed and explicit consent, contractual necessity, a legal requirement, or a legitimate interest. Allow a data subject to withdraw consent at any time, without this affecting the lawfulness of earlier processing. |
|
| Personal Data Protection Act, comprehensive consent-based regime |
An app that collects, uses, or discloses the personal data of an individual in Singapore must obtain the individual's consent, or rely on a Part 3 or Schedule exception, and must state its purpose for the collection, use, or disclosure. |
|
| Act on the Protection of Personal Data |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Slovakia; the Act's own text is not confirmed, and any Slovak-specific addition to that basis is unverified. |
|
| Zakon o varstvu osebnih podatkov (ZVOP-2), Personal Data Protection Act |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Slovenia, and expect ZVOP-2's own institutional and procedural rules to govern rather than a GDPR restatement alone. |
|
| Telecommunications Act 2009, Confidentiality and Consent Duties |
If operating as a licensed telecommunications service provider in Solomon Islands, do not collect, use, maintain, or disclose a consumer's information without the consumer's consent, other than publishing the consumer's name, address, and listed telephone number in a directory. Take all reasonable steps to keep a consumer's communications confidential, and do not intercept, monitor, alter, or modify the content of a message without authorisation. |
|
| Data Protection Act No. 005 of 2023 |
Establish a lawful basis before processing personal data, such as the data subject's consent, the performance of a contract, a legal obligation, or the data subject having intentionally made the data public, and process it fairly and transparently. Where you rely on consent, be able to prove the data subject gave it. |
|
| Protection of Personal Information Act 4 of 2013 (POPIA) |
Obtain a lawful basis, such as the data subject's consent, before processing personal information, and limit processing to the purpose for which it was collected. |
|
| Personal Information Protection Act, comprehensive regime and lawful bases |
An app that collects, uses, or discloses the personal data of individuals in South Korea must establish one of PIPA's lawful processing grounds, most commonly consent or a documented legitimate interest justification, before processing, and must confine use to the stated purpose of collection. |
|
| PIPC Guideline on Processing Publicly Available Data for AI Development and Services |
An app training AI models on personal data scraped from publicly accessible Korean web sources must rely on and document PIPA Art. 15(1)(6)'s legitimate interest basis, since publicly available data is not exempt from PIPA. |
|
| Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive Regime |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Spain, and rely on a statute-rank Spanish or EU norm rather than mere regulation if the basis is public interest or legal obligation, per LOPDGDD Article 8. |
|
| Personal Data Protection Act, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Sri Lanka, including a voiceprint or faceprint, must have a lawful basis under Schedule I, ordinarily consent, contract necessity, or a legitimate interest satisfying a balancing test, and must give a data subject a way to seek review of a decision based solely on automated processing that has created or is likely to create an irreversible and continuous impact on their rights. |
|
| Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed |
Have a lawful basis, such as a contract, a legal obligation, vital interests, a public interest task, official authority, a legitimate interest that does not override the data subject's rights, or the data subject's consent, before processing personal data. Where processing rests on consent, present the request separately from other matters, in clear and simple language, and let the data subject withdraw consent as easily as it was given. |
|
| Dataskyddslagen (Data Protection Act), GDPR-Complementing Provisions |
Establish a GDPR Article 6 lawful basis before processing personal data of a person in Sweden; Dataskyddslagen adds domestic legal bases mainly for public-sector processing, not a modification of the private-sector Article 6 list. |
|
| Federal Act on Data Protection (nFADP), General Processing Principles |
Have a justification, consent, an overriding private or public interest, or a legal basis, before processing personal data of a person in Switzerland in a way that would otherwise violate their personality rights. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data |
Determine a lawful basis under one of the grounds article 7 lists before processing personal data, such as the data subject's consent to a specific purpose, a contractual or legal obligation, or a court order. |
|
| Personal Data Protection Act (個人資料保護法) |
Collect, process, or use the personal data of an individual in Taiwan only for a specific purpose and on one of the Act's stated lawful bases, and confine use to the purpose stated at collection unless a further basis under Article 16 or 20 applies. |
|
| Law on the Protection of Personal Data, comprehensive regime |
An app that collects or processes the personal data of individuals in Tajikistan must obtain the subject's consent, limit processing to a specific, predetermined, lawful purpose, and notify the subject of the data collected about them with a right to correction. |
|
| Personal Data Protection Act, comprehensive regime |
An app that collects, uses, or discloses the personal data of an individual in Thailand must obtain consent by default before processing, unless a Section 24 statutory exception applies. |
|
| Constitution of the Democratic Republic of Timor-Leste, Section 38(2) (Personal data deferred to statute) |
Rely on Section 38's own two operative rules, the access right and the sensitive-category consent bar, rather than on a statutory definition of personal data, because none exists to scope a Timor-Leste deployment against. |
|
| Loi n° 2019-014, protection des données à caractère personnel |
Have a lawful basis for processing personal data, generally the data subject's consent, or rely on a legal obligation, a public interest task, contract performance, or the data subject's vital interests. |
|
| Privacy Act 2025, comprehensive personal information protection regime from a date not yet set |
Do not process personal information unless the data subject has given specific, informed consent that has not been withdrawn, or another lawful basis in section 27 applies, such as contractual necessity, a legal obligation, vital interests or the public interest. |
|
| Data Protection Act, 2011 |
Whether or not Part III or Part IV binds you yet, be responsible for the personal information under your control, identify the purpose of collection before or at the time of collection, and get the individual's knowledge and consent for its collection, use or disclosure. |
|
| Organic Act on the Protection of Personal Data |
Do not make providing a service or granting a benefit conditional on a person accepting that their data be processed or reused for a purpose other than the one it was collected for. Do not communicate personal data to a third party without the person's express consent given in a form leaving a written trace, unless a listed public security, defense or criminal prosecution exception applies. |
|
| Personal Data Protection Law (KVKK), comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in Turkey must establish one of KVKK Art. 5's lawful bases, most commonly explicit consent, before processing, and must confine use to the stated purpose of collection. |
|
| Law on Information About Private Life, comprehensive regime |
An app that collects or processes the personal information of individuals in Turkmenistan must obtain the subject's written consent, may not expand its use beyond the original purpose without further consent, and may not subcontract its collection or processing duties to another party by contract. |
|
| Data Protection and Privacy Act, 2019, comprehensive personal-data regime |
Obtain the data subject's prior consent before collecting or processing their personal data, unless a specific ground in section 7(2) applies, such as a legal requirement, a public duty, national security, a contract with the data subject, or a legal obligation. |
|
| Draft Law No. 8153 on Personal Data Protection (GDPR-Aligned Reform) proposed |
Once enacted, process personal data of a person in Ukraine only under a lawful basis, applying the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. Once enacted, rely on legitimate interests as a legal basis for processing personal data of a person in Ukraine, alongside consent and contract, under the draft's expansion of legal bases toward GDPR Article 6. |
|
| Law of Ukraine On the Protection of Personal Data |
Establish a lawful basis before processing personal data of a person in Ukraine under Law No. 2297-VI. |
|
| ADGM Data Protection Regulations, comprehensive regime |
An app that is a controller or processor established in or targeting the ADGM free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier, including one derived from a photo, video, or audio recording. |
|
| DIFC Data Protection Law, comprehensive regime |
An app that is a controller or processor established in or targeting the DIFC free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier used to uniquely identify a natural person, including one derived from a photo, video, or audio recording. |
|
| Federal Decree-Law on the Protection of Personal Data, comprehensive regime and lawful basis |
An app that collects, uses, or discloses the personal data of an individual in the onshore UAE must establish a lawful basis under PDPL Art. 4, ordinarily consent, and must obtain the Data Subject's explicit consent before processing a faceprint, voiceprint, or other identity-linked biometric identifier, including one derived from a photo, video, or audio recording, since biometric data is a category of Sensitive Personal Data. |
|
| UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025 |
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies. Do not rely on the recognised legitimate interests basis if you are a public authority exercising your own core functions; a necessity test still applies even though no balancing test is required. |
|
| Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended |
Obtain the data subject's free, prior, express, and informed consent, documented in writing, before processing their personal data, unless a listed exception applies (data from public sources, a legal mandate, a state function, or a contractual, scientific, or professional relationship). Communicate personal data to a third party only for a purpose directly tied to the sender's and recipient's legitimate interest, only with the data subject's prior consent, and only after telling them the purpose of the communication and identifying the recipient. |
|
| Law on Personal Data, comprehensive regime and lawful bases |
An app that collects, uses, or discloses the personal data of individuals in Uzbekistan must establish one of the Law's lawful bases, most commonly the subject's consent, before processing. |
|
| Data Protection and Privacy Act 2024, comprehensive personal data protection regime |
Do not process personal data unless it is processed fairly and transparently for an explicit, specified and legitimate purpose under one of the lawful purposes in section 5, such as the data subject's consent, contract necessity, a legal obligation, the public interest, or a legitimate interest that does not override the data subject's rights. Be able to demonstrate evidence of a data subject's consent, present any request for consent clearly and separately from other matters, obtain it for each specific purpose, and let the data subject withdraw it at any time, free of charge. |
|
| Virginia Consumer Data Protection Act (VCDPA), general applicability and controller/processor duties |
Obtain a Virginia consumer's opt-in consent before processing sensitive data, and treat information a consumer restricted to a specific audience as covered personal data, not as exempt publicly available information. Do not sell precise geolocation data collected from Virginia residents. A 2026 amendment added an outright ban on that sale. |
|
| Data Protection Act, 2021, personal data processing framework |
Before processing personal data, establish a lawful basis such as consent, a contract, a legal obligation, or a legitimate interest, and process it fairly, transparently, and only for the purpose collected. Tell a data subject of the right to withdraw consent before they give it, present the request separately from other matters in clear and plain language, be able to prove the consent was given, and destroy immediately every piece of personal data collected after a withdrawal. +1 more |
Sensitive categories
163 laws, 158 places| Place | Law | What it asks, as read here |
|---|---|---|
| Alabama Personal Data Protection Act (HB 351), sensitive data and biometric consent from , in 7 months |
Once effective, obtain an Alabama consumer's consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual, racial or ethnic origin, religious belief, a health diagnosis, sexual orientation, citizenship or immigration status, or precise geolocation. |
|
| Law No. 124/2024, special categories of personal data, criminal records and children's data |
Do not process sensitive data, meaning racial or ethnic origin, political opinions, religious or philosophical belief, trade union membership, genetic data, biometric data, health records, or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent to a specified purpose. Treat a facial image or other biometric identifier as sensitive data requiring one of Article 9's listed exceptions before you may process it; the definition names a facial image as an example, so a derived faceprint is covered and the definition is not confined to a raw recording. +3 more |
|
| Loi n° 18-07 relative à la protection des personnes physiques, catégories de données sensibles et biométriques |
Do not process data revealing racial or ethnic origin, political opinions, religious or philosophical convictions or trade-union membership, nor health data including genetic data, unless the data subject gave express consent, a public interest or legal provision authorises it, or the ANPDP authorised it. Where you process genetic data as a doctor or biologist for preventive medicine, diagnosis or care, or process data a person has manifestly made public, or process sensitive data to establish or defend a legal claim, rely on the specific article 18 ground rather than express consent. |
|
| LQPD, special categories, children and criminal-offence data |
Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union affiliation, or process genetic data, biometric data used to uniquely identify a person, health data, or data about sex life or sexual orientation, unless a listed Article 9(2) exception applies, most commonly the data subject's explicit consent. Confine any processing of personal data about a person's criminal convictions or offences, or related security measures, to what is strictly necessary and authorised by law or supervised by a public authority with adequate safeguards. +1 more |
|
| Law on the Protection of Personal Data, sensitive data categories |
Do not process sensitive data (philosophical or political convictions, party or union membership, religious faith, private life, racial or ethnic origin, or health and sex life including genetic data) unless a legal provision permits it or the Agência de Protecção de Dados authorises it on one of its listed grounds, such as the data subject's unequivocal, express and written consent. Process health and sex-life data, including genetic data, only with the data subject's or their legal representative's unequivocal, express and written consent or the APD's authorisation, unless it is for preventive medicine, medical diagnosis, consented medical care, health-service management, a medical emergency, or the public interest, and only through a health professional bound by professional secrecy. +1 more |
|
| Data Protection Act, 2013, sensitive personal data |
Do not process sensitive personal data, meaning information about a data subject's physical or mental health, sexual orientation, political opinions, religious or similar beliefs, or the commission or alleged commission of an offence, unless the data subject has given explicit consent to the processing. Where consent is not obtained, process sensitive personal data only on a listed ground such as an employment law obligation, protecting the vital interests of the data subject or another person, medical treatment by a healthcare professional, legal proceedings or advice, the administration of justice, or exercising a function conferred by law. |
|
| Ley 25.326, sensitive data categories and health data |
Do not require a person to provide sensitive data (racial or ethnic origin, political opinions, religious, philosophical, or moral convictions, union membership, or health or sexual-life information). Collect and process sensitive data only for a reason of general interest authorized by law, or for statistical or scientific purposes where the data subject cannot be identified. +2 more |
|
| Law on Protection of Personal Data, special category data |
An app that processes a category of special data covered by Art. 12 from a person in Armenia must obtain the data subject's consent or rely on a specific legal provision authorizing the processing, and must stop processing immediately once that basis or purpose no longer applies. |
|
| Privacy Act 1988 (Cth), Schedule 1, Sensitive and Biometric Information |
Do not collect sensitive information about an individual, including biometric information used for automated biometric verification or identification, or a biometric template, unless the individual consents and the collection is reasonably necessary for the entity's functions, or a listed exception in Australian Privacy Principle 3.4 applies. |
|
| GDPR Article 9, Special Categories of Personal Data Including Biometric Data, as Applied in Austria |
Obtain explicit consent, or establish another GDPR Article 9(2) basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available. |
Show the other 153 laws
| Law on Personal Data, special categories of personal data |
An app that processes race, nationality, family-life, religious-belief, health, or conviction data from a person in Azerbaijan must have a specific statutory ground for that processing under Art. 9.7; biometric data is not one of these special categories under Azerbaijan's law and is governed instead by the Act's ordinary processing conditions. |
|
| Personal Data Protection Law, sensitive personal data |
An app processing an individual's race, ethnic origin, political or philosophical opinions, religious beliefs, union affiliation, criminal record, or health or sexual status in Bahrain must obtain the Data Subject's consent unless the Art. 5 public-availability exception applies; biometric data is not part of this Sensitive Personal Data category, so it is governed instead by the Art. 15 prior-authorisation rule. |
|
| Personal Data Protection Act, 2026, sensitive personal data and biometric data |
An app that derives a facial image, voiceprint, or other biometric identifier from a person in Bangladesh must treat it as Sensitive Personal Data and satisfy one of section 7's narrower lawful-basis conditions, ordinarily the data principal's specific consent, before processing it. |
|
| Data Protection Act, 2019, a child's consent and sensitive personal data |
Do not process sensitive personal data, including biometric data, unless the data subject consents or a specific statutory ground applies. Process a child's personal data only where consent is given or authorised by the child's parent or guardian, a child being a person under the age of 18. +2 more |
|
| Law of the Republic of Belarus On Personal Data Protection, special personal data |
Do not process special personal data, meaning data on race or nationality, political opinions, trade union membership, religious or other beliefs, sex life or health, administrative or criminal records, or biometric or genetic data, without the personal data subject's consent, unless a listed exception applies, such as the data having been publicly disclosed by the subject, a labor relations purpose, or medical care by a bound professional, under Article 8. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, données sensibles et mineurs |
Do not process sensitive personal data, including racial or ethnic origin, political opinions, religion or beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about a person's sex life or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public. Verify that a minor is at least sixteen years old before processing their personal data in connection with an information society service offered directly to them, and otherwise obtain the consent of the holder of parental responsibility, making reasonable efforts to verify that consent given the technology available. +2 more |
|
| Information, Communications and Media Act of Bhutan 2018, sensitive personal data and biometric information |
An app that derives a voiceprint, faceprint, or other biometric identifier from a person in Bhutan must treat it as Sensitive Personal Data or Information and obtain the subject's express written permission before collecting it, unless the information is itself freely available or accessible in the public domain. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina, special categories, criminal-conviction data and children's consent |
Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union affiliation, genetic data, biometric data for unique identification, health data, or data about a person's sex life or sexual orientation, unless a listed exception in Article 11 applies, such as the person's explicit consent. Process personal data about a criminal conviction or offence only under the supervision of a public authority or where a special law authorizes it with safeguards for the person's rights, and keep any register of criminal convictions exclusively under a public authority's control, under Article 12. +1 more |
|
| Data Protection Act, 2024, sensitive personal data and children's data |
Obtain consent given or authorised by a parent or a person with parental duties over a child under sixteen before processing that child's personal data for an information-society service offered directly to them; a child who is sixteen may consent themselves. Do not process racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, or data concerning sex life or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public. +1 more |
|
| LGPD, sensitive personal data and children's data |
Obtain specific, highlighted consent, or another article 11 legal basis, before processing sensitive personal data such as health, genetic, or biometric data. Process a child's or adolescent's personal data only with specific, highlighted consent from at least one parent or legal guardian, except to contact the parent once without storing the data or to protect the child, and never condition participation in a game, application, or other activity on more personal data than the activity strictly needs. |
|
| GDPR Article 9 and PDPA Employment and National-ID-Number Rules from a date not yet set |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in Bulgaria. Do not use the Bulgarian national identification number (ЕГН) as a sole service identifier, and grant public access to it only where required by law, per commentary describing the PDPA; verify against the Act's own text before relying on it. |
|
| Personal Data Protection Law, sensitive personal data categories |
Obtain the data subject's express consent before collecting or processing sensitive personal data, including data about health, biometric or genetic characteristics, sex life, racial or ethnic origin, political, philosophical, religious or trade union opinions or activity, morals, or criminal investigations, prosecutions, convictions and administrative or safety measures, unless a specific statutory exception applies. Restrict any processing of personal data about offenses, convictions or safety measures to a court or public authority acting within its legal powers, a public body managing a public service after the CIL's concurring opinion, or a legal auxiliary acting strictly within duties assigned to it. |
|
| Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories |
Do not process personal data revealing philosophical, ideological or political beliefs or penalty, religion, political party or trade union affiliation, racial or ethnic origin, privacy, or health and sex life including genetic data, unless the data subject has expressly consented with a guarantee of non-discrimination, a legal authorisation applies with the same guarantee, or another of the law's listed grounds is met. Process health and sex life data, including genetic data, only through a health professional bound by professional secrecy, only for preventive medicine, medical diagnosis, care or health service management, and only once notified to the CNPD under article 23, with adequate information security measures. +1 more |
|
| Cambodia's Draft Law on Personal Data Protection, sensitive personal data proposed |
If enacted as drafted, a data controller would be prohibited from processing sensitive personal data, which would include a facial image, fingerprints, or another biometric identifier, genetic data, health data, and data revealing racial origin, political opinions, religious or philosophical beliefs, or trade union membership, unless it also met one of nine listed conditions, such as the data subject's explicit consent. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, données sensibles et mineurs |
Get a data subject's explicit consent, and apply extra security and organisational safeguards, before processing a sensitive category of data such as racial origin, biometric or genetic data, health data, or political, religious, or trade union information. Get authorisation from a holder of parental responsibility before processing a minor's personal data, including for a direct offer of information society services to a child. +2 more |
|
| Loi n°007/PR/2015, traitement des catégories particulières de données (données sensibles et biométriques) |
Do not process biometric data, or data revealing racial or ethnic origin, filiation, political opinion, religious or philosophical belief, trade-union membership, sex, health, or sexual life, unless the data subject gives explicit written consent or a listed statutory exception applies. Process a minor's personal data only in keeping with the representation rules the law sets for the exercise of the minor's own rights. |
|
| Personal Information Protection Law, Sensitive Personal Information |
Obtain the individual's separate, explicit consent before processing any sensitive personal information, including a biometric identifier such as a faceprint or voiceprint, in addition to any general consent already collected. Process biometric identifiers only for a specific, necessary purpose and under strict protective measures, and obtain guardian consent before processing a minor's data. |
|
| Ley 1581 de 2012, Sensitive Categories and Children's Data |
Before processing sensitive personal data, including data revealing racial or ethnic origin, political opinion, religious or philosophical belief, union or human rights organization membership, health, sexual life, or biometric data, obtain the data subject's explicit authorization; processing sensitive personal data is otherwise prohibited. Process sensitive personal data without the data subject's explicit authorization only where it protects the data subject's vital interest and they cannot consent, where a not for profit political, philosophical, religious or union body processes it about its own members without disclosing it to third parties, where it is needed to establish, exercise or defend a right in a judicial proceeding, or where it serves a historical, statistical or scientific purpose and the data subject's identity is suppressed. +1 more |
|
| HB 24-1058, Protect Privacy of Biological Data |
Treat data generated by measuring an individual's biological, genetic, biochemical, physiological, or neural properties, or central or peripheral nervous system activity, as sensitive data requiring the consumer's affirmative opt-in consent before you process it. |
|
| SB 24-041, Protecting Minors' Online Data |
Get opt-in consent, parental consent for a minor under 13, before processing a minor's personal data for targeted advertising, sale, or profiling with legal or similarly significant effects. |
|
| Law on the Protection of Personal Data, sensitive personal data |
Do not collect or process data revealing political, philosophical or religious opinions, trade union membership, or health or sexual life data, without the data subject's express consent, unless a listed exception applies, such as safeguarding a life the data subject cannot consent to protect. Process data on offenses, convictions or security measures only as a court, a public authority, a body managing a public service, a legal auxiliary acting within your legal duties, or another legal person managing a dispute over an offense of which you were the victim. |
|
| Connecticut Data Privacy Act, sensitive data and biometric data definitions |
Obtain a Connecticut consumer's opt-in consent before processing sensitive data, including biometric data generated to uniquely identify the individual. |
|
| GDPR Article 9, Special Categories Including Biometric Data |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in the Czech Republic; Act 110/2019 supplies no separate Czech basis. |
|
| Law No. 2013-450 on the Protection of Personal Data, sensitive categories of personal data |
Do not process personal data revealing a person's racial, ethnic or regional origin, political opinion, religious or philosophical belief, trade-union membership, sex life, or genetic data concerning health, unless a listed exception applies. Confine processing under the non-profit exception to the body's own members or to people with regular contact related to its purposes, and do not disclose the data to a third party without their consent. |
|
| Digital Code, Title III, sensitive personal data and minors |
Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, refugee or stateless status, trade union membership, sex life, or health, unless a statutory exception applies. Rely on the data subject's explicit consent, a manifestly public disclosure by the data subject, a vital interest, an important public interest, a public authority's public-interest mission, public-statistics legislation, or supervised preventive or occupational medicine as the only grounds for processing a prohibited special category of data. +1 more |
|
| GDPR Article 9, Special Categories of Personal Data as Applied in Denmark |
Ground the processing of any biometric identifier of a person in Denmark, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent. |
|
| Digital Code, Book I: sensitive categories of personal data and the minor's consent |
Do not process sensitive personal data (racial or ethnic origin, political or philosophical opinions, religious opinions or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, or health data) without the data subject's express consent or another statutory ground. Let a minor consent alone to an information-society service's processing of their personal data only from age 16, obtain the consent of the person holding parental authority below that age, and make reasonable efforts to verify it given the technology available. |
|
| Ley No. 172-13 sobre Protección Integral de los Datos Personales, special and sensitive categories of data |
Obtain the data subject's free, conscious, and voluntary consent before forming a file, bank, or register that reveals their sensitive data (political opinions, religious or philosophical convictions, union affiliation, or health or sex-life information). Do not create a data file, bank, or register that stores sensitive data except as this law provides, even though a church, religious association, clinic, hospital, or political or union organization may still keep a register of its own members. +3 more |
|
| LOPDP, categorías especiales de datos personales |
Do not process personal data without a lawful basis under the Act, and obtain explicit consent before processing a sensitive category of data unless another enumerated ground applies. Do not process sensitive data at all unless the data subject has given explicit consent or one of the other grounds article 26 lists applies. +1 more |
|
| Egypt Personal Data Protection Law, Sensitive Personal Data and a child's data |
Obtain a parent or legal guardian's consent before processing a child's personal data, and do not condition a child's participation in a game, competition, or activity on personal data beyond what participation requires. Obtain the Data Subject's explicit written consent before any dealing with their Sensitive Personal Data, outside the cases a law authorises, on top of the Center's licence. |
|
| Ley para la Protección de Datos Personales, sensitive personal data and children |
Do not compel a person to provide sensitive personal data (data touching physical or moral characteristics, or facts of private life whose misuse could cause discrimination or gravely harm honor or privacy, including religious belief, ethnic origin, political or union affiliation, sexual preference, health, or biometric or genetic information); take it only with the data subject's express and unequivocal consent after telling them of their right to withhold it. Obtain a sensitive data subject's consent in writing, by an autograph signature or its equivalent, and apply the Progressive Exercise of Faculties principle to a child's consent to provide their personal data. +3 more |
|
| GDPR Article 9, Special Categories of Personal Data as Applied in Estonia |
Ground the processing of any biometric identifier of a person in Estonia, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent. |
|
| Data Protection Act, 2022, sensitive personal information |
Do not process sensitive personal information, including genetic data, data related to children, data related to offences or criminal sentences, biometric data, or information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, gender, or health or sex life, unless a listed exemption applies. Obtain prior parental consent before processing personal information under the parental control exemption, and rely on consent, legal necessity, or Commission authorisation for another listed exemption to the prohibition. +1 more |
|
| Personal Data Protection Proclamation, sensitive personal data and minors |
Do not process sensitive personal data, including genetic or biometric data, unless a listed exception applies, such as the data subject's specific written consent. Process a minor's personal data only with the consent or authorization of a parent, guardian, or tutor, or where necessary to the minor's vitally important interest, and never for marketing, profiling, or merging of profiles. +2 more |
|
| GDPR Article 9, Special Categories of Personal Data Including Biometric Data |
Obtain explicit consent, or establish another Article 9(2) basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available. Treat any biometric identifier your system derives through its own technical processing as special category data, even where the underlying image or audio was lawfully public. |
|
| GDPR Article 9 and Data Protection Act Section 6, Special Categories in Finland |
Ground the processing of any biometric identifier of a person in Finland, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent, unless it falls within one of the eight contexts Data Protection Act Section 6 lists, none of which is biometric-specific. |
|
| Florida Digital Bill of Rights, sensitive data and biometric data definitions |
Obtain a qualifying Florida consumer's consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual, if you meet FDBR's $1 billion-plus controller threshold. Display the notice "NOTICE: This website may sell your sensitive personal data" and obtain consent before selling a qualifying consumer's sensitive personal data. |
|
| GDPR Article 9 Special Categories, as Implemented by Loi 78-17 Article 6 |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in France; Loi 78-17 Article 6 supplies no separate French basis beyond the Regulation's own list. |
|
| Law No. 025/2023, sensitive categories of personal data and children's data |
Process a minor's personal data only on their own consent once they turn eighteen, or otherwise only with the express authorization of the holder of parental authority, and confirm by some means that the consent you rely on is theirs. Do not collect or process data revealing racial or ethnic origin, political, philosophical or religious opinions, trade-union membership, biometric or genetic data, or data on health or sex life, unless a listed exception applies, such as the data subject's own express consent, a non-profit body's processing of its own members, data the person made public, or preventive medicine and care administered by a bound health professional. +3 more |
|
| Personal Data Protection and Privacy Act, 2025, sensitive personal data and children's data from a date not yet set |
Do not process genetic or biometric data, or data revealing racial origin, political opinions or health status, unless you have both a lawful basis and one of the Act's listed conditions, such as the data subject's explicit consent. Obtain parental or guardian consent before processing the personal data of a person under the age of 18, and put that child's best interests and privacy first. |
|
| Law on Personal Data Protection, special categories of data |
An app that processes special-category data, including biometric or genetic data, from a person in Georgia must rely on one of Art. 6's 20 lawful grounds, most commonly the data subject's explicit consent. |
|
| GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in Germany |
Where you deploy a biometric time clock, access control system, or voice-authentication system for employees in Germany, satisfy BDSG Section 26(3)'s conditions rather than relying on employee consent as the sole basis. |
|
| Data Protection Act, special personal data |
Do not process special personal data, including a person's ethnicity, race, political opinion, religious belief, health, sexual life, or criminal behaviour, or the personal data of a child under parental control, unless a listed exception applies. Process special personal data only where it is necessary or the data subject consents, treating processing as necessary where it exercises or performs a right or obligation the law imposes on an employer. +2 more |
|
| Data Protection Act, No. 1 of 2023, sensitive personal data from a date not yet set |
Do not process sensitive personal data, including health, genetic, biometric, sex life, political or religious information, except on one of the Act's listed grounds, ordinarily the data subject's written consent. Where you rely on a ground other than consent, confirm it is one the Act lists: an employment right or obligation, protecting the data subject's or another person's interests where consent cannot reasonably be obtained, medical purposes handled under a duty of confidentiality, legal proceedings or advice, the administration of justice, a government function, or information the data subject has already made public. |
|
| Guam Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act of 2019 |
Do not intentionally disclose, or threaten to disclose, a private intimate image of an identifiable person without that person's consent, when you know or recklessly disregard that the image is private, the person did not consent, or the person is identifiable. |
|
| Ley de Transparencia y Acceso a la Información Pública, protección de datos personales y hábeas data |
Do not force a person to provide personal data that could cause them discrimination, or patrimonial or moral harm or risk. |
|
| Infotörvény Definitions, Biometric and Special-Category Data |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric data of a person in Hungary; the Infotorveny's own definition tracks GDPR Article 4(14) without narrowing or expanding it. |
|
| Act No. 90/2018 Articles 3(14) and 9, Special Categories in Iceland |
Ground the processing of any biometric identifier of a person in Iceland, including a faceprint captured for unique identification, on an Article 9(2)-style exception such as explicit consent, under Act No. 90/2018 Article 9. |
|
| Genetic Testing Privacy Act, restrictions on employers from a date not yet set |
Do not access, request, or require an individual's private genetic information, or require a genetic test, as a condition of a hiring, promotion, retention, or other related employment decision in Idaho if you employ five or more persons. |
|
| Indiana Consumer Data Protection Act, sensitive data and biometric data definitions |
Obtain an Indiana consumer's consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual, or process a known child's sensitive data only under COPPA's consent framework. |
|
| Electronic Commerce Law (2003), Personal Data Chapter |
An app that stores, processes, or distributes data revealing a Iranian resident's tribal or ethnic origin, religious or moral belief, ethical characteristics, or physical, psychological, or sexual condition needs their explicit consent first. Any other collection or processing of personal data needs consent for a specified, described purpose, must be limited to that purpose, must stay accurate, and must let the person access their own data with a right to have it corrected or completely removed. The law names no biometric category, so a voiceprint or faceprint is not subject to a heightened consent, retention, or destruction standard beyond the general consent-based rule, and nothing in this chapter conditions moving personal data out of Iran or requires notifying anyone after a security incident. Violating Article 58's sensitive-data consent rule is a criminal offense (one to three years' imprisonment), state-prosecuted rather than privately actionable. |
|
| GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in Ireland |
Where you process special category data, including biometric data, about an employee in Ireland, ground it in a legitimate argument tied to vital interests or another Article 9(2) condition with a public-interest character, and put suitable and specific safeguarding measures in place, under Data Protection Act 2018 Section 46. Treat any biometric identifier your system derives through its own technical processing as GDPR Article 9 special category data, whether or not the source photo or audio was publicly available. |
|
| GDPR Article 9 Special Categories and Codice Privacy Article 167(2) |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, genetic, or health data of a person in Italy, and treat unlawful special-category processing as a Codice Privacy Article 167(2) criminal exposure, not only an administrative one. |
|
| Data Protection Act, 2020, conditions for processing sensitive personal data |
Do not process genetic data, biometric data, health data or any other sensitive personal data unless at least one condition in section 24 is met in addition to a condition in section 23. Obtain the data subject's consent in writing before processing their sensitive personal data on the consent condition, and stop processing on that condition once the consent is withdrawn. +1 more |
|
| Personal Data Protection Law, sensitive personal data and biometric data |
An app that processes biometric data about an individual in Jordan, including a faceprint or voiceprint, must treat it as Sensitive Personal Data and obtain consent or rely on one of the Law's enumerated exceptions, and must not retain it beyond the processing purpose unless legislation specifies otherwise. Whether Jordan requires a heightened, explicit-consent standard specifically for biometric processing, beyond ordinary consent, is not confirmed. |
|
| Genetic testing nondiscrimination in health-benefit insurance underwriting from a date not yet set |
Do not require, request, or use a Kansas health-benefit-plan applicant's or enrollee's genetic test results to condition coverage, set rates, or adjust premiums. |
|
| Student Data Privacy Act, biometric data collection consent from a date not yet set |
Obtain the written consent of an adult student, or the parent or legal guardian of a minor student, before a Kansas school district collects the student's biometric data, including a fingerprint, retina or iris pattern, voiceprint, DNA sequence, facial characteristic, or handwriting sample. Obtain that same written consent before using a device or mechanism to assess a Kansas student's physiological or emotional state. |
|
| Kentucky Consumer Data Protection Act, sensitive data and biometric data definitions |
Obtain a Kentucky consumer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual. |
|
| Data Protection Act, 2019, sensitive personal data |
Do not process biometric, genetic, health or other sensitive personal data unless a specific ground under section 45 applies, in addition to the Act's general lawful-basis requirement. Do not process health data unless you are a health-care provider or a person bound by professional secrecy. |
|
| Data Protection Act 2025, children and individuals lacking capacity from a date not yet set |
On commencement, obtain consent from a parent, guardian, or other appropriate legal representative before relying on the consent of a data subject who is under eighteen or otherwise lacks legal capacity, wherever the Act requires the data subject's consent for a lawful basis, retention, an automated decision, or a cross-border transfer. On commencement, obtain that same consent from a parent, guardian, or other appropriate legal representative before relying on a data subject's voluntary provision of personal data as a lawful basis, where the data subject is under eighteen or otherwise lacks legal capacity. |
|
| Law No. 06/L-082 on Protection of Personal Data, special categories, children and criminal-offence data |
Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about sex life or sexual orientation, unless a listed Article 8(2) exception applies, most commonly the data subject's explicit consent. Confine any processing of personal data about a person's criminal convictions or offences, or related security measures, to what an official authority controls under the relevant law. +1 more |
|
| Digital Code, special categories of personal data |
An app that processes biometric data for the digital identification of a Kyrgyzstani data subject, including a voiceprint or faceprint, must satisfy one of Art. 80(2)'s narrow lawful grounds before processing; such processing is prohibited by default otherwise. The Code itself supplies no illustrative list of biometric modalities for this general provision. |
|
| Personal Data Processing Law Article 25(2), Special Categories in Latvia |
Ground the processing of any biometric identifier of a person in Latvia, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent, under Personal Data Processing Law Article 25(2). |
|
| Law No. 81/2018, Part V, health, genetic identity and sexual-life data |
Do not collect or process data that reveals, directly or indirectly, the health status, genetic identity or sexual life of a person in Lebanon. Rely on one of the four exceptions only: the person made the data public or explicitly agreed to the processing and no legal impediment applies, the processing is necessary to establish a medical diagnosis or provide medical treatment by a healthcare professional, a right is being proved or defended before a court, or you hold a licence under Article 97. |
|
| Data Protection Act, 2011, sensitive personal information |
Do not process personal information concerning a child who is subject to parental control, or a data subject's spiritual, religious or philosophical beliefs, race or ethnic origin, trade union membership, political affiliation, health, sexual life, or criminal behaviour, unless a listed exemption applies. Obtain prior parental consent before processing personal information under the parental control exemption, and rely on consent, legal necessity, or Commission authorisation for another listed exemption to the prohibition. +1 more |
|
| DSG Special-Category Data and Datenschutzstelle Biometric-Data Concept in Liechtenstein |
Ground the processing of any biometric identifier of a person in Liechtenstein, including a faceprint or voiceprint captured for unique identification, on a DSG condition equivalent to GDPR Article 9(2), such as explicit consent. |
|
| GDPR Article 9, Special Categories of Personal Data as Applied in Lithuania |
Ground the processing of any biometric identifier of a person in Lithuania, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent. |
|
| Louisiana Data Privacy Act (Act No. 502), sensitive and biometric data from , in 3 months |
Obtain a Louisiana consumer's consent before selling sensitive data, if you meet the LDPA's revenue-from-sale applicability threshold. |
|
| GDPR Article 9, Special Categories of Personal Data as Applied in Luxembourg |
Ground the processing of any biometric identifier of a person in Luxembourg, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent; no Luxembourg-specific addition to this baseline was found. |
|
| Law No. 2014-038, sensitive personal data |
Do not process sensitive data, including racial origin, biometric, genetic, political opinion, religious or other belief, trade union, health, or sex-life data, unless one of the law's listed exceptions applies, such as the data subject's express consent. Restrict processing personal data about offenses, convictions, or safety measures to a court, a public authority managing a public service acting within its legal powers, or a legal auxiliary acting within the strict needs of a legally assigned mission. |
|
| Maldives Personal Data Protection Bill, special categories of personal data proposed |
If enacted as drafted, a Controller would not be able to process special categories of personal data, which would include biometric data used to identify a person uniquely, genetic data and health data, unless one of the instances section 17 lists applied, such as the data subject's explicit consent to one or more specified purposes. If enacted as drafted, a Controller relying on legitimate interest would have to weigh the position of a child, whose interests and fundamental rights the Bill treats as a particular reason that interest is overridden. |
|
| Loi n° 2013-015, sensitive data and offence records |
Do not process sensitive data (data relating to religious, philosophical, political, or union opinions or activities; sexual life or racial origin; health; social measures; prosecutions; or penal or administrative sanctions) unless the Autorité de Protection des Données à Caractère Personnel has defined appropriate safeguards for it and one of the listed conditions applies, such as necessity to safeguard the life of the data subject or a third party who cannot consent. Limit any processing of personal data relating to offences and convictions to a court or public authority acting within its legal powers, a judicial auxiliary acting for the strict needs of duties the law assigns it, or another legal person handling, for the strict needs of managing contentious matters, offences of which it was itself the victim. |
|
| Maryland Online Data Privacy Act (MODPA), sensitive data and biometric consent |
Do not collect, process, or share sensitive data, including genetic or biometric data, unless strictly necessary to provide a product or service the consumer requested. MODPA supplies no separate consent-only path around this necessity requirement. Never sell sensitive data. MODPA bans the sale of sensitive data outright. +1 more |
|
| Loi n° 2017-020, catégories sensibles de données |
Before collecting or processing data revealing racial, ethnic, linguistic, or regional origin, political opinion, religious or philosophical belief, trade union membership, sexual life, genetic data, or health, confirm one of the Act's ten listed exceptions applies. Process data on criminal offences, convictions, or security measures only if you are a court, a public authority, a public-service body, or a legal auxiliary acting within your legal mission. +1 more |
|
| Data Protection Act 2017, special categories of personal data |
Do not process a special category of personal data (including biometric data uniquely identifying a person) unless one of the specific grounds in section 29(1) applies, in addition to the Act's general lawful-processing requirement. |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares, sensitive personal data |
Obtain the data subject's express, written consent, by autograph signature, electronic signature, or another authentication mechanism, before processing their sensitive personal data, unless a statutory exception applies. Do not create a database of sensitive personal data unless its creation serves a legitimate, specific purpose consistent with your explicit activities or aims. |
|
| Genetic test; informed consent from a date not yet set |
Obtain a test subject's written, informed consent before a physician orders a presymptomatic or predictive genetic test in Michigan. |
|
| Minnesota Consumer Data Privacy Act, sensitive data and biometric consent |
Obtain a Minnesota consumer's opt-in consent before processing biometric data, or any other sensitive data, when that biometric data is processed for the purpose of uniquely identifying the individual. |
|
| Genetic information, insurer and employer restrictions, confidentiality duty |
Do not require or request an individual's or their blood relative's genetic information or a genetic test, or consider genetic information or a genetic test result without the individual's approval, when making a health-plan eligibility, premium, coverage, or renewal decision. Do not use an employee's or job applicant's genetic information or genetic test results to discriminate against them or restrict a right or benefit otherwise due them, unless a statutory exception applies. +1 more |
|
| Moldova Law No. 195/2024, special categories, a child's consent and conviction data |
Obtain explicit consent or another enumerated exception before processing biometric data, including facial images, of a person in Moldova for unique identification. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data or data concerning health, sex life or sexual orientation, unless one of the article 9(2) cases applies. +2 more |
|
| Loi sur la Protection des Données Personnelles, données sensibles et mineurs |
Do not process sensitive data, meaning data revealing political, religious, philosophical, or trade union opinions, racial or ethnic origin, genetic data, biometric data used to identify a person uniquely, or data about health, sex life, or sexual orientation, unless one of the listed exceptions applies. Where you rely on a person's explicit consent to process their sensitive data, keep evidence that the consent was specific, informed, and given by a clear positive act, since a law can also bar that prohibition from ever being lifted by consent alone. +2 more |
|
| Law on Protection of Personal Data, sensitive personal information |
An app processing a Mongolian data subject's ethnicity, religion, belief, health, correspondence, genetic or biometric information, criminal-sentence status, sexual orientation, gender identity, or sexual-relations information must satisfy one of the Law's lawful-basis or health or legal-claim grounds before processing; this category expressly includes biometric and genetic information, so an app declaring only a biometric activity is still bound by this instrument, not only by the biometric_privacy instrument. |
|
| Montana Consumer Data Privacy Act, sensitive data and biometric data definitions |
Obtain opt-in consent before processing a Montana consumer's genetic or biometric data collected to uniquely identify them. |
|
| Law on Personal Data Protection, special categories of data from a date not yet set |
Do not process special categories of data, meaning data on racial or ethnic origin, political, religious or other beliefs, social origin, trade union membership, health, sex life or sexual orientation, biometric data, or criminal and misdemeanour records, unless one of the exceptions in Article 13 applies, starting with the data subject's consent. Do not process personal data relating to criminal offences, criminal or misdemeanour penalties or security measures except by, or under the supervision of, the competent state authority, and only with the safeguards the law requires, under Article 14. |
|
| Law No. 09-08, sensitive personal data and offense records |
Do not process sensitive data, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or health data including genetic data, without a specific legal authorization, the CNDP's prior authorization, or the data subject's express consent. Do not process personal data about offenses, criminal convictions, or security measures unless you are a court, a public authority, a public service body, or an auxiliary of justice acting within your legal duties. |
|
| Privacy Act, 2075, sensitive information and biometric data |
An app that holds a voiceprint, faceprint, or other biometric identifier of a person in Nepal must have the person's consent before disclosing or publishing it to a third party, and must have consent or lawful authorization before recording a private conversation to derive it in the first place, though Nepal's Privacy Act does not treat biometric data as a heightened "sensitive information" category the way it treats caste, political affiliation, religion, health, or sexual orientation. |
|
| UAVG Articles 30-33 and 46, Health, Criminal-Conviction, and National-ID-Number Data |
Obtain a GDPR Article 9(2) basis before processing health, genetic, racial or ethnic origin, political opinion, or religious-belief data of a person in the Netherlands, following UAVG's Chapter 3 exceptions where one applies to your processing purpose. Do not treat the citizen service number (BSN) as a general-purpose identifier; UAVG Article 46 restricts its processing. |
|
| New Hampshire Data Privacy Act, sensitive data and biometric data definitions |
Obtain a New Hampshire consumer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual, racial or ethnic origin, religious belief, a health condition, sexual orientation, citizenship or immigration status, a known child's data, or precise geolocation. |
|
| New Jersey Data Privacy Act, sensitive data and biometric definition |
Obtain a New Jersey consumer's opt-in consent before processing sensitive data, including biometric data, financial account information, or pregnancy-related health data. |
|
| Genetic Information Privacy Act from a date not yet set |
Obtain a person's informed, written consent before obtaining their genetic information or samples for genetic analysis, or before performing genetic analysis or collecting, retaining, transmitting, or using their genetic information, unless a statutory exception applies. |
|
| Ley No. 787, Ley de Protección de Datos Personales, sensitive categories of data |
Process sensitive personal data (racial or ethnic origin, political affiliation, religious or philosophical belief, union membership, health or sex life, criminal record, or financial and credit information) only on a general-interest ground recognized by law, the data subject's consent, or a judicial order. Do not create a data file that stores sensitive personal data except as this Act provides, even though a commercial company or nonprofit association may still keep a file of its own members' data. +4 more |
|
| Loi n° 2022-59, données sensibles, de santé et biométriques |
Do not process data revealing racial, ethnic or regional origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life, health, genetic or biometric data, social measures, or criminal or administrative sanctions, unless the data subject made it manifestly public themselves, gave written consent, or another listed exception applies. Process health data only for the listed purposes, such as preventive medicine, diagnosis, care administration, public health, safeguarding vital interests, administering social-protection benefits, a legal claim, or ethics-committee-approved research, and restrict that processing to medical professionals or persons bound by professional secrecy. +2 more |
|
| Nigeria Data Protection Act, 2023, sensitive personal data and a child's data |
Obtain a data subject's consent before processing sensitive personal data, and before processing the personal data of a child. Do not seek, give or accept consent in any circumstance that may propagate atrocities, hate, child rights violations or criminal acts. |
|
| Law on Personal Data Protection (LPDP), special categories, a child's consent and biometric, health and genetic data |
The processing of a child's personal data for an information society service offered directly to the child is lawful where the child is at least 14 years old, or, if younger, only where a parent or another holder of parental responsibility has given or authorised the consent; make reasonable efforts to verify that consent, taking available technology into account. Once Chapter II takes effect, do not process a special category of personal data unless one of Article 13's exceptions applies, such as the data subject's explicit consent, a necessity ground tied to employment or social security law, vital interests, or an important public interest carried out with suitable safeguards. +1 more |
|
| Personal Data Act Chapter 3 and GDPR Article 9, Special Categories in Norway |
Ground the processing of any biometric identifier of a person in Norway, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent. |
|
| Oklahoma Consumer Data Privacy Act, sensitive data and biometric data definitions from , in 3 months |
Obtain an Oklahoma consumer's opt-in consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual. |
|
| Oregon Consumer Privacy Act, sensitive data and biometric data definitions |
Obtain a lawful basis and, for sensitive data, opt-in consent before processing an Oregon consumer's genetic or biometric data. |
|
| Ley 81 de 2019, sensitive personal data |
Do not transfer sensitive personal data (data touching a person's intimate sphere, or whose misuse could enable discrimination or serious risk, including racial or ethnic origin, religious or philosophical belief, union affiliation, political opinion, health, sexual orientation, or genetic or biometric data) unless the data subject gave explicit authorization or a narrow statutory exception applies. Take a data subject's consent to processing sensitive health data only when it is prior, irrefutable and express, a higher bar than ordinary consent. +1 more |
|
| Ley N° 7593/2025, tratamiento de datos sensibles y categorías especiales from , in 14 months |
Treat racial or ethnic origin, religious or political belief, health, sexual orientation, genetic data and biometric data used to uniquely identify a person as sensitive data, and process it only on one of the law's narrow grounds. Do not process sensitive data at all unless one of the narrow grounds article 20 lists applies, such as the data subject's own consent or data the person has made public. +1 more |
|
| House Bill 78, sensitive data and biometric data definitions proposed |
If enacted, obtain opt-in consent before processing sensitive data, including biometric or genetic data collected to uniquely identify an individual. |
|
| Ley 29733, sensitive personal data and minors |
For sensitive data (biometric data that by itself identifies a person, racial or ethnic origin, income, political, religious, philosophical or moral opinions, union affiliation, or health or sex-life information), obtain the titleholder's consent in writing, in addition to the general consent requirements, and do not process it without that written consent unless a law authorizes processing without it on important public-interest grounds. Process health data without consent only where necessary, in a risk situation, for the titleholder's medical or surgical prevention, diagnosis, or treatment at a health establishment or by a health-sciences professional observing professional secrecy, for a public-interest or public-health reason the Ministry of Health has qualified as such, or for an epidemiological or similar study using an adequate dissociation procedure. |
|
| GDPR Article 9, Special Categories of Personal Data as Applied in Portugal |
Ground the processing of any biometric identifier of a person in Portugal, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent. |
|
| Ley para la Protección de la Privacidad Cibernética de los Niños y Jóvenes (children's online privacy) |
Do not publish or disclose a known minor user's personal information beyond their name and city of residence without the minor's and a parent's or guardian's consent. Do not profile a known minor through fully automated processing of their personal information unless the profiling is reasonably necessary to the service or serves a compelling, minor-protective purpose, and safeguards are in place. |
|
| Québec | Express consent for sensitive personal information |
Obtain the person's express consent, not an inferred or bundled one, before using sensitive personal information for a new purpose or communicating it to a third person. |
| Law No. 29-2019, special categories of personal data |
Do not collect or process personal data revealing ethnic or regional origin, filiation, political opinions, religious or philosophical beliefs, trade union membership, sex life, genetic data, or a person's state of health, unless one of the article 15 grounds applies. Process genetic data itself only to verify a genetic link for a person's identification, or for the prevention or repression of a specific criminal offence, in the administration of proof in court. +2 more |
|
| Rhode Island Data Transparency and Privacy Protection Act, sensitive data and biometric data definitions |
Obtain a Rhode Island customer's opt-in consent before processing sensitive data, including genetic or biometric data processed to uniquely identify the individual. |
|
| GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules from a date not yet set |
Obtain explicit consent or express legal authorization, with adequate protective measures, before using genetic, biometric, or health data of a person in Romania to drive an automated decision or profile, per commentary describing Law 190/2018. |
|
| Federal Law No. 152-FZ, Articles 10-11, Special Categories and the Biometric Data Definition |
Obtain written consent before processing biometric personal data of a person in Russia, including an identifier such as a facial image or voice recording that would fall under Article 11's general definition, unless a narrow Article 11(2) statutory exception applies. Never make provision of biometric data a condition of service to a person in Russia, except where a separate federal law affirmatively mandates identification. |
|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
Process sensitive personal data, including genetic or biometric information, race, health status, criminal records, religious or philosophical beliefs, political opinion, sexual life or family details, only on one of the five grounds article 10 lists, such as the data subject's consent, a vital interest, public health, or archiving, scientific or statistical purposes. Before processing personal data you know belongs to a child under sixteen, obtain the consent of a holder of parental responsibility over the child, unless the processing is necessary to protect the child's vital interest. +1 more |
|
| Data Protection Act, 2018, processing of sensitive personal data from a date not yet set |
Do not process sensitive personal data, meaning information about a data subject's physical or mental health, sexual orientation, political opinions, religious or similar beliefs, or an offence they committed or are alleged to have committed, unless a listed exception applies. Process sensitive personal data only with the data subject's explicit consent, for an employment right or obligation, to protect vital interests where consent cannot be given or has been unreasonably withheld, for medical purposes by a healthcare professional or an equivalent confidant, for legal proceedings, advice, or the administration of justice, or where the data subject has deliberately made the information public. |
|
| Data Protection Act, sensitive personal data |
Do not process a special category of sensitive personal data (racial or ethnic origin, political opinion, religious belief, physical or mental health, sexual orientation, or criminal or financial record) unless a listed ground applies, the person has given explicit consent, or the person already published it themselves. Process sensitive personal data for health or medical purposes only through a health practitioner or someone bound by professional confidentiality, and only for preventive medicine, public health, medical diagnosis, medical research, or managing health and hospital care services. +1 more |
|
| San Marino Law No. 171, special categories of personal data |
Obtain explicit consent or another Article 8(2) exception before capturing or storing a biometric identifier of a person in San Marino; Article 8(1) prohibits biometric processing for unique identification absent one. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data or data concerning health, sex life or sexual orientation, unless one of the article 8(2) cases applies. +2 more |
|
| Lei n.º 03/2016, sensitive categories and suspect records |
Before processing a sensitive category of data (political, religious, trade-union or philosophical affiliation, racial or ethnic origin, private life, health, sex life, or genetic data), obtain the holder's explicit authorization, rely on a specific legal provision, or obtain NAPPD authorization for an important public interest. Where you process health or sex-life data, including genetic data, for preventive medicine, diagnosis, care or health-service management, do so only through a health professional or another person bound by professional secrecy, notify NAPPD of the processing, and secure it with appropriate information-security measures. +1 more |
|
| Personal Data Protection Law, sensitive data and biometric processing |
An app that derives a faceprint, voiceprint, or other identity-linked biometric identifier from an individual in Saudi Arabia, for any purpose the purpose-based Sensitive Data definition would reach, must obtain the Data Subject's explicit consent before processing it, and must destroy it once the processing purpose is fulfilled or consent is withdrawn. |
|
| Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, catégories sensibles de données |
Before collecting or processing data revealing racial, ethnic, or regional origin, political opinion, religious or philosophical belief, trade union membership, sexual life, genetic data, or health, confirm one of the Act's narrow exceptions applies. Process data on criminal offences, convictions, or security measures only if you are a court, a public authority, a public-service body, or a legal auxiliary acting within your legal mission. +1 more |
|
| Law on Personal Data Protection, special categories of personal data and minors |
Do not process data revealing racial or ethnic origin, political opinion, religious or philosophical belief, or trade union membership, or process genetic data, biometric data for unique identification, health data, or data about a person's sex life or sexual orientation, unless a listed exception applies, such as the person's explicit consent for one or more specified purposes. Where a minor is 15 years old or older, their own consent is enough to process personal data for an information-society service; below that age, get consent from the parent exercising parental responsibility or another legal representative, and take reasonable steps to verify it. +2 more |
|
| Data Protection Act, 2023, sensitive data and data of minors |
Do not process race, ethnic origin, biometric, genetic, political, religious or health-related personal data unless a specific exception in section 22 applies. Obtain consent from a parent or legal guardian before processing the personal data of a person below 18 years, and verify that such consent has been given. |
|
| GDPR Article 9 and Act Section 78, National Birth Number from a date not yet set |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric, genetic, or health data of a person in Slovakia. Do not process or disclose a Slovak birth number (rodne cislo) without the data subject's explicit consent or their own prior disclosure, per commentary describing Act Section 78; verify this against the Act's own text before relying on it. |
|
| Data Protection Act, 2023, sensitive personal data and children's consent |
Obtain consent from a parent or other appropriate legal representative before processing the personal data of a child or of an individual otherwise lacking legal capacity, unless the child is sixteen or older and is asking for an electronic service themselves. Apply appropriate processes to verify the identity and age of a data subject and of a representative giving consent for them. |
|
| Protection of Personal Information Act, special personal information and children |
Do not process special personal information, including a person's biometric information, health, race, or political persuasion, unless a listed ground under sections 27 to 33 applies. Do not process a child's personal information unless a competent person has given prior consent, another listed ground in section 35(1) applies, or the Information Regulator has authorised the processing as being in the public interest with appropriate safeguards. +2 more |
|
| Genetic Data Privacy Act, definitions, consent, and consumer rights |
Obtain a South Dakota consumer's opt-in express consent, separately for collection, third-party transfer, research use, retention beyond the initial test, and marketing use of genetic data or a biological sample, if you operate a direct-to-consumer genetic testing service. Honor a consumer's revocation of consent and destroy their biological sample within 30 days. |
|
| Personal Information Protection Act, sensitive information and biometric data |
An app that derives a faceprint, voiceprint, or other unique biometric identifier from a Korean data subject, including one derived from a photo, video, or audio recording, must treat it as sensitive information under PIPA Art. 23 and obtain separate, specific consent before processing it. |
|
| GDPR Article 9 and AEPD Biometric Guidance, Special Categories |
Do not deploy a biometric employee time-and-attendance system in Spain on the Estatuto de los Trabajadores alone; the AEPD's own guidance holds that statute does not itself authorize biometric means, and a genuine GDPR Article 9(2) basis is needed. Do not run a facial-recognition matching system against members of the public without a valid Article 9.2 exception; the AEPD categorically prohibited exactly that in its Mercadona enforcement and fined it EUR 2,520,000. |
|
| Personal Data Protection Act, special categories and biometric data |
An app that derives a faceprint, voiceprint, or other biometric identifier used to uniquely identify a person in Sri Lanka must treat it as a special category of personal data and satisfy one of Schedule II's conditions, ordinarily the data subject's consent, before processing it. |
|
| Draft Law on the Protection of Privacy and Personal Data, special categories, children and criminal data proposed |
Process a child's personal data based on consent only where the child is at least sixteen, or where a legal representative has consented for a younger child after you take reasonable steps to verify that; never process a child's personal data in a way inconsistent with the child's interest. Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data about a person's sexual behaviour or orientation, unless a listed exception applies, such as the data subject's explicit consent. +1 more |
|
| FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data |
Obtain express, affirmative consent, opt-in rather than opt-out, before creating a voiceprint or other biometric identifier from a person in Switzerland, or establish another Article 6 basis for the processing. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data, sensitive personal data |
Obtain the data subject's written and explicit consent before processing their sensitive personal data, unless a legally authorized case applies. Obtain the consent of a child's legal guardian before processing a child's personal data, and where a child takes part in a game, competition or other activity that calls for personal data, collect no more than participation requires. |
|
| Personal Data Protection Act, 2022, sensitive personal data |
Obtain the data subject's prior written consent before processing genetic, biometric or other sensitive personal data, including data related to a child, and where the data subject is a minor or otherwise unable to consent, seek that consent from a parent, guardian or other legal representative. |
|
| Tennessee Information Protection Act, sensitive data and biometric definition |
Obtain a Tennessee consumer's consent before processing sensitive data, including biometric or genetic data processed to uniquely identify the individual. |
|
| Texas Data Privacy and Security Act, sensitive data and biometric consent |
Obtain a Texas consumer's opt-in consent before processing sensitive data, including biometric or genetic data collected to uniquely identify the individual, racial or ethnic origin, religious belief, a health diagnosis, sexuality, immigration status, or precise geolocation. Follow the Children's Online Privacy Protection Act's consent framework, not TDPSA's general consent rule, when processing a known child's sensitive data. |
|
| Personal Data Protection Act, sensitive and biometric categories |
An app that captures or processes a faceprint, iris scan, fingerprint, voiceprint, or other biometric identifier from an individual in Thailand must obtain that individual's explicit consent under Section 26 before processing, unless a statutory exception applies. |
|
| Constitution of Timor-Leste, Section 38(3) (Sensitive categories of personal data) |
Obtain the person's consent before processing data on their private life, political or philosophical convictions, religious faith, party or trade union membership, or ethnical origin. Do not rely on a legitimate-interest, contract or public-task basis for those categories: the Constitution prohibits processing them without consent and states no alternative. |
|
| Loi n° 2019-014, données sensibles |
Do not collect or process data revealing racial or ethnic origin, filiation, political, religious or philosophical opinions, trade union membership, sex life, or health or genetic data, unless a listed exception applies, such as the data subject's written consent or a vital interest that prevents them from consenting. Process data on criminal offenses, convictions or security measures only as a court, a public authority, a body managing a public service, or a legal auxiliary acting within your legal duties. +1 more |
|
| Privacy Act 2025, sensitive personal information and children from a date not yet set |
Do not process sensitive personal information, including biometric data such as a voiceprint or facial image, unless a section 27 basis is met and, in addition, the data subject has given and not withdrawn consent to that specific purpose or another section 28 ground applies. Before processing a child's personal information, or that of an individual lacking capacity to consent, obtain the consent of a parent or other appropriate legal guardian and apply appropriate age and consent verification mechanisms, including government approved identification documents. |
|
| Data Protection Act, 2011, sensitive personal information |
Section 6(h)'s general principle already binds everyone who handles, stores or processes personal information: do not process sensitive personal information (racial or ethnic origin, political affiliation or trade union membership, religious belief, physical or mental health, sexual orientation, or criminal or financial record) unless a written law otherwise provides for it. Once Part III is in force, a public body may process sensitive personal information only with the person's consent, or where a listed exception applies, such as health care treatment by a health care professional, information the person already made public, research under section 43, law enforcement or national security, or determining access to social services. +1 more |
|
| Organic Act on the Protection of Personal Data, sensitive categories and minors |
Do not process personal data about a person's criminal offences, their detection, prosecution, penalties, preventive measures or judicial record. Do not process data revealing racial or genetic origin, religious, political, philosophical or trade union opinions, or health, unless the person gives express written consent, the data is already manifestly public, or the processing serves a historical, scientific or vital-interest purpose. +2 more |
|
| Personal Data Protection Law (KVKK), special categories and biometric data |
An app that captures or processes biometric data, including a voiceprint or faceprint, from a person in Turkey must treat it as special-category data under KVKK Art. 6 and obtain explicit consent or rely on one of Art. 6(3)'s other statutory grounds before processing, even though the Act does not itself define what counts as biometric data. |
|
| Law on Information About Private Life, special categories of personal information |
An app processing a Turkmen data subject's nationality, skin color, religious attitude, political conviction, health, or intimate-life data must have the subject's written consent, rely on publicly available data, or fall within a narrow list of justice, health, or membership-organization exceptions; such processing is prohibited by default otherwise. |
|
| Data Protection and Privacy Act, 2019, children and special personal data |
Do not collect or process a child's personal data unless the child's parent, guardian, or another person with authority to decide for the child has given prior consent, or the collection or processing is necessary to comply with the law or is for research or statistical purposes. Do not collect or process personal data about an individual's religious or philosophical beliefs, political opinion, sexual life, financial information, or health status or medical records, unless a listed exception applies. +1 more |
|
| R (Bridges) v Chief Constable of South Wales Police, Automated Facial Recognition by Police |
If you are a public authority deploying facial recognition or another biometric surveillance system in the United Kingdom, put an adequate legal framework and a proper Data Protection Impact Assessment in place before deployment, not after. |
|
| UK GDPR Article 9, Special Categories of Personal Data Including Biometric Data |
Obtain explicit consent, or establish another UK GDPR Article 9(2) or Data Protection Act 2018 Schedule 1 basis, before capturing or storing a faceprint, voiceprint, or other biometric identifier derived from a photo, video, or audio recording, whether or not the source recording itself was publicly available. Treat biometric data as covered from the moment you collect it once you have determined a purpose of unique identification, not only from the point you actually perform identification or verification, per the ICO's Biometric recognition guidance. |
|
| HIPAA Privacy Rule |
Do not use or disclose protected health information except as the Privacy Rule permits or requires, and limit use and disclosure to the minimum necessary. |
|
| Video Privacy Protection Act |
Obtain the consumer's informed, written consent before disclosing personally identifiable information about the consumer's video-viewing history to a third party. |
|
| Ley N° 18.331, sensitive personal data and health data |
Do not require anyone to provide sensitive data (racial or ethnic origin, political opinion, religious or moral conviction, union affiliation, health, or sexual life), and process what you do collect only with the data subject's express written consent. Collect and process sensitive data absent that consent only where an interest-general law authorizes it, the requesting body has a legal mandate to do so, or the purpose is statistical or scientific and the data is disassociated from its subject. +2 more |
|
| Genetic Information Privacy Act |
Obtain a Utah consumer's initial express consent before collecting, using, or disclosing their genetic data through a direct-to-consumer genetic testing product or service, and give them a public privacy notice describing your data practices. Obtain separate express consent before transferring genetic data outside your vendors, using it beyond the primary testing purpose, or retaining a biological sample after testing. +1 more |
|
| Law on Personal Data, special personal data |
An app processing an Uzbek data subject's racial, social-origin, political, religious, ideological, trade-union, health, private-life, or criminal-record data must have the subject's written consent, rely on a state-security purpose, or rely on data the subject has already published in publicly available sources; such processing is prohibited by default otherwise. |
|
| Data Protection and Privacy Act 2024, special categories and children's personal data |
Do not process special categories of personal data, including biometric data such as a voiceprint or facial image, genetic data, or data revealing racial or ethnic origin, political opinions, trade-union membership, religious belief, health or sexual life, unless an exception in section 6(2) applies, such as the data subject's explicit consent or a safeguarded public-interest ground. Before processing a child's personal data, obtain the consent of a parent, carer or legal guardian, communicate with the child in clear and plain language, and put appropriate age-verification mechanisms in place, unless the processing is in the child's legitimate interests or is necessary for preventive or counselling services offered directly to the child. |
|
| Vermont Data Privacy and Online Surveillance Act, sensitive data and biometric data definitions from , in 15 months |
Once in force, treat any genetic or biometric data you collect about a Vermont consumer as sensitive data requiring opt-in consent, without needing to show the data was collected to identify that person. |
|
| Virginia Consumer Data Protection Act, sensitive data and biometric data definitions |
Obtain a Virginia consumer's opt-in consent before processing sensitive data, including genetic or biometric data collected to uniquely identify the individual. |
|
| HB 1155, My Health My Data Act |
Obtain separate, affirmative opt-in consent before collecting or sharing a Washington consumer's health data, including any biometric identifier used to infer a health condition, whether captured live or extracted from a stored photo, video, or audio recording. Obtain a further signed authorization before selling consumer health data. +1 more |
|
| Data Protection Act, 2021, sensitive personal data, children and vulnerable persons |
Obtain explicit consent, or rely on another applicable ground, before processing sensitive personal data, including biometric or genetic data, a child's data, political opinions, or health information. Process a child's or a vulnerable person's personal data only with the consent of their parent, legal guardian or a person exercising parental responsibility. +3 more |
|
| Cyber and Data Protection Act, sensitive, genetic, biometric and health data |
Obtain the data subject's written consent, withdrawable at any time, before processing sensitive data such as race, political opinion, religion, trade union membership, sex life, health or criminal history. Do not process genetic data, biometric data or health data at all unless the data subject has given written consent. +2 more |
|
| Cyber and Data Protection Regulations 2024, children's information and automated decisions |
Obtain the consent of a parent or legal guardian before processing a child's personal information, and do not subject a child's data to automated decision-making that affects the child's rights. Make reasonable efforts to verify that the consent to process a child's personal information was given or authorised by the parent or legal guardian, taking available technology into account. |
Telephone contact
38 laws, 21 places| Place | Law | What it asks, as read here |
|---|---|---|
| Do Not Call Register Act 2006, Unsolicited Marketing Faxes |
Treat consent as express, or reasonably inferred from the account-holder's conduct and business or other relationships; never treat a number as consenting merely because it has been published, treat express consent that does not itself state a period as lapsing three months after it is given, and check any ACMA determination on inferring consent for a marketing fax sent to a business number. |
|
| Do Not Call Register Act 2006, Unsolicited Telemarketing Calls |
Treat consent as express, or reasonably inferred from the account-holder's conduct and business or other relationships; never treat a number as consenting merely because it has been published, and treat express consent that does not itself state a period as lapsing three months after it is given. |
|
| Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 |
Do not make, cause to be made, or attempt to make a telemarketing call that is not a research call on a weekday before 9am or after 8pm, a Saturday before 9am or after 5pm, a Sunday, or a listed national public holiday (or its in-lieu weekday holiday), unless the account-holder or their nominee gave express advance consent to that day or time. |
|
| Automatic Dialing-Announcing Devices Act |
Before disseminating the prerecorded message, give the person called an unrecorded, natural-voice announcement stating the nature of the call and the caller's name and either an address or telephone number, ask whether the person consents to hear the prerecorded message, and, if the message uses an artificial voice (one generated or significantly altered using artificial intelligence), disclose that fact; disconnect the device when either party ends the call. |
|
| Consumers Legal Remedies Act, Unsolicited Prerecorded Telephone Messages |
Before disseminating an unsolicited prerecorded telephone message, first give the person answering an unrecorded, natural-voice statement of your name or the organization you represent and either your address or telephone number, and get that person's consent to listen to the prerecorded message. |
|
| Unsolicited Advertisements by Facsimile Machine |
Do not use a fax machine, computer, or other device to send, or cause to be sent, an unsolicited advertisement to a fax machine, where you, the recipient, or both are located in California, unless the recipient gave prior express invitation or permission. |
|
| Unsolicited and Unwanted Telephone Solicitations Act |
Do not use the Do Not Call list for any purpose other than compliance, deny a subscriber's right to be placed on it, add a subscriber to it without their knowledge or consent, sell or lease it to anyone other than a telephone solicitor, or charge a fee to place a number on it. |
|
| Connecticut Action for Unsolicited Facsimile or Automated Telephone Advertising Messages |
Do not use a machine that electronically transmits facsimiles through connection with a telephone network, or a device that automatically transmits a recorded telephone message, to transmit unsolicited advertising material or an unsolicited telephone message offering to sell goods or services. |
|
| Connecticut Telemarketing Act (Conn. Gen. Stat. 42-284 to 42-289, as substantially rewritten by Public Act 23-98) |
Do not make, or cause to be made, a telephonic sales call (a live-voice, automated-dialing, recorded-message, soundboard, over-the-top, text or media message call, but not electronic mail) to a consumer without the consumer's prior express written consent: a written agreement, signed by the consumer, that discloses the means of contact and the number to be contacted and clearly and conspicuously authorizes advertisements or telemarketing messages by those means. Do not knowingly, or while avoiding knowledge, provide substantial assistance or support that enables a person you know or avoid knowing is engaged in telemarketing fraud or a violation of these sections to initiate, originate, route or transmit a voice communication or telephonic sales call; this does not reach designing, manufacturing or distributing a component, product or technology with a commercially significant use beyond circumventing these rules, a provider offering general Internet access, or a terminating network provider completing a call. |
|
| Delaware Harassment Statute (Telephone Solicitation Clause) |
Do not, with intent to harass, annoy or alarm another person, communicate with that person by telephone, telegraph, mail or any other written or electronic means, including an intrastate sales call, in a manner you know is likely to cause annoyance or alarm. Do not knowingly permit a telephone under your control to be used for a purpose this section prohibits. +1 more |
Show the other 28 laws
| Florida Telephone Solicitation Act (section 501.059 as rewritten in 2021) |
Obtain the called party's prior express written consent, naming the seller and the number to be called, before placing an unsolicited telephonic sales call, text message, or voicemail transmission that uses an automated system for the selection and dialing of telephone numbers or a recorded message played on connection. |
|
| Gesetz gegen den unlauteren Wettbewerb, Documentation of Consent to Telephone Advertising |
Document a consumer's prior express consent to telephone advertising in an appropriate form at the time the consent is given. |
|
| Gesetz gegen den unlauteren Wettbewerb, Telephone Advertising Consent |
Obtain a consumer's prior express consent before advertising to them by telephone call. Before advertising by telephone call to another business or professional market participant (not a consumer), obtain at least that participant's presumed consent, judged by whether the call fits their known or reasonably inferable interests. |
|
| Illinois Automatic Telephone Dialers Act |
Do not play a prerecorded sales message placed by an autodialer without the called party's consent. Disconnect within 30 seconds after the call ends; if that is not technically feasible, have a live operator state their name, the name, address, and telephone number of the business or organization represented, and the purpose of the call, and ask at the outset whether the called person consents to hear the prerecorded message. +1 more |
|
| Illinois Telephone Solicitations Act |
As a live operator, immediately state your name, the name of the business or organization you represent, and the purpose of the call, ask at the outset whether the called person consents to the solicitation, and do not continue without that consent. |
|
| Irish ePrivacy Regulations |
Get the called subscriber's or user's prior consent, or check it is recorded as consenting in the National Directory Database, before making an automated-calling or telephone call for direct marketing to a mobile telephone number. |
|
| Maryland prerecorded-message dialing and caller number blocking rules |
Do not use an automated dialing, push-button, or tone-activated system with a prerecorded message to solicit a purchase, lease, or rental, offer a gift or prize, conduct a poll, or request survey information used to solicit purchases, unless you have a preexisting business relationship with, or the consent of, the person called. |
|
| Maryland Stop the Spam Calls Act of 2023 |
Before making, or causing to be made, a telephone solicitation that uses an automated system for the selection or dialing of telephone numbers, or that plays a recorded message when the call connects, get the called party's prior express written consent: a signed written agreement (an electronic signature can qualify) naming the number to be called, with a clear and conspicuous disclosure that signing authorizes those automated or recorded solicitations and that the called party need not sign it, or agree to it as a condition of any purchase. Do not make a telephone solicitation, including one made through automated dialing or a recorded message, between 8 p.m. and 8 a.m. in the called party's time zone, more than three times to the same person in a 24-hour period on the same subject matter regardless of the numbers used, or while intentionally altering your voice to disguise your identity in order to defraud, confuse, or injure the called party or obtain their personal information. |
|
| Telemarketing Solicitation Act |
Do not place an unsolicited telephonic sales call to a consumer whose name and telephone number appear on the office's current no sales solicitation calls listing, call between 8 p.m. and 8 a.m. local time at the consumer's location, send the solicitation by fax, or use a recorded message device. |
|
| Home Solicitation Sales Act, Telephone Solicitation Rules (as amended effective 2003) |
Do not make a telephone solicitation that consists in whole or in part of a recorded message. |
|
| Telephone Companies as Common Carriers Act, Recorded Commercial Advertising and Caller Identification (section 25 as amended effective 1999) |
Do not use a telephone line to contact a subscriber at a residential, business or toll-free number to deliver a recorded message presenting commercial advertising unless the subscriber has knowingly and voluntarily requested, consented to, permitted or authorized the contact, or has knowingly and voluntarily given you the subscriber's telephone number; do not transfer, assign or sell that authorization without the subscriber's written permission. |
|
| Unlawful Automated Telephone Solicitation |
Do not use an automated telephone system, device, or facsimile machine to dial a telephone number and play a recorded message to offer or sell goods or services, convey information soliciting a purchase, solicit information, gather data, or promote a political campaign. |
|
| Unsolicited Advertisement Facsimile Transmissions |
Do not use a telephone facsimile machine, computer, or other device to send an unsolicited advertisement, material advertising the commercial availability or quality of property, goods, or a service, to a telephone facsimile machine without the recipient's prior express invitation or permission; this does not reach public safety information sent by a law enforcement or public safety entity. |
|
| Nevada Deceptive Trade Practice Rules for Telephone and Text Solicitations |
Do not solicit a person by telephone at their residence between 8 p.m. and 9 a.m. |
|
| Nevada Device for Automatic Dialing and Announcing Statute |
Do not use such a device to place a call received in Nevada between 8 p.m. and 9 a.m., or a call-back or second call to a number whose occupant ended the original call. |
|
| Telephone Solicitation Act of 2022 |
Obtain the called party's prior express written consent before making, or knowingly allowing, a commercial telephonic sales call, text message or voicemail that uses an automated system for the selection or dialing of telephone numbers or plays a recorded message when the call connects; the consent must be a signed written agreement (an electronic signature counts where federal law or state contract law recognizes it) that names the telephone number to be called and discloses clearly and conspicuously that the called party need not sign it to buy anything. |
|
| Oregon Automatic Dialing and Announcing Device Statute (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026) |
Use such a device to call a subscriber only between 8 a.m. and 8 p.m., and no more than three times in 24 hours, unless one of the government-list exceptions applies or you are responding directly to the subscriber's own message; you may rely on a mobile number's area code to decide whether the subscriber is in Oregon. |
|
| Oregon Unlawful Telephone Solicitations Act (as amended by 2025 Or. Laws ch. 580, effective January 1, 2026) |
Do not initiate a telephone solicitation outside the hours of 8 a.m. to 8 p.m., or more than three separate times to a party within a 24-hour period, unless you have an established business relationship with the party (a transaction with the party within the preceding 18 months). |
|
| Telemarketer Registration Act |
Do not initiate a robocall to a residential, business or wireless line without the called party's prior express written consent: a signed agreement (an electronic signature can qualify) naming the number, clearly and conspicuously disclosing consent to solicitations including a robocall or text message, and stating that consent is not a condition of purchase; do not use an unfair or deceptive practice to obtain it. |
|
| Automatic Dial Announcing Devices |
Do not use the device for random or sequential number dialing when it plays a recorded message on connection, for a solicitation call terminating in Texas before noon or after 9 p.m. on a Sunday or before 9 a.m. or after 9 p.m. on a weekday or Saturday, or for a collection call at an hour the federal Fair Debt Collection Practices Act prohibits. Make the device disconnect within five seconds after either party ends the call, or, if it cannot, have a live operator introduce the call and receive the called person's oral consent before the message begins. |
|
| Prohibited Telephonic and Facsimile Communications for Solicitation |
Do not make, or use an automatic dial announcing device to make, a telephone call for the purpose of making a sale to a number you know or should know is a mobile telephone the called person will be charged for that specific call, unless that person has consented to receiving it from you or from the business you are calling for. Do not make or cause a facsimile transmission for the purpose of a solicitation or sale to a device the recipient will be charged for, unless the recipient consented before the transmission, and do not make or cause a solicitation facsimile transmission between 11 p.m. and 7 a.m. |
|
| PECR, Automated Calls, Facsimile and Live Telephone Calls for Direct Marketing |
Get the called subscriber's prior consent before transmitting, or instigating the transmission of, recorded matter for direct marketing purposes by an automated calling or communication system (one that can automatically dial a sequence of numbers and play sounds that are not live speech), and either do not prevent presentation of your calling line's identity or present a line on which you can be contacted. Get the called individual's prior consent before making an unsolicited call marketing claims management services; there is no do-not-call-register or existing-customer exception for this subject. +1 more |
|
| Telemarketing Sales Rule |
Do not deliver a prerecorded telemarketing message to induce a purchase or a charitable contribution without the recipient's prior signed written agreement to receive prerecorded calls from that seller, obtained separately from any purchase requirement. |
|
| Telephone Consumer Protection Act, Autodialer and Artificial or Prerecorded Voice Calls |
Obtain the called party's prior express consent before initiating any call or text to a wireless number using an automatic telephone dialing system or an artificial or prerecorded voice, and before delivering a prerecorded-voice message to a residential line, unless the call is for an emergency purpose. For a telemarketing robocall or robotext (one that includes or introduces an advertisement or constitutes telemarketing), obtain the recipient's prior express written consent, in a signed writing naming the seller and the telephone number to be called, before sending it; a non-marketing, informational autodialed call or text needs only prior express consent, not a signed writing. |
|
| Virginia Automatic Dialing-Announcing Devices Act |
Before an automatic dialing-announcing device (equipment that selects and dials numbers and plays a prerecorded or synthesized voice message) delivers a commercial telephone solicitation to a subscriber in Virginia, either have the subscriber's knowing or voluntary request, consent, permission or authorization to receive it, or have a live operator disclose the sending entity's name, the message's purpose, the kinds of goods or services promoted and, if applicable, that the message seeks payment or a commitment of funds, and obtain the subscriber's consent before the message is delivered. |
|
| Virginia Telephone Privacy Protection Act |
Do not initiate, or cause to be initiated, a telephone or text-message solicitation to a Virginia number or resident outside 8:00 a.m. to 9:00 p.m. local time at the contacted person's location, unless that person has given prior consent. |
|
| Automatic Dialing and Announcing Device Act |
Do not use an automatic dialing and announcing device, a system that automatically dials numbers and plays a recorded or artificial voice message once a connection is made (including one that goes to voicemail), for commercial solicitation to a Washington telephone customer; commercial solicitation means the unsolicited initiation of a call to encourage a purchase of property, goods or services or to wrongfully obtain anything of value, and the section states no consent-based exception. Do not substantially assist another person in transmitting a commercial solicitation described above while knowing or consciously avoiding knowledge that the initiator is violating this section, unless you are a telecommunications provider that both complied with federal telemarketing rules and implemented a reasonably effective plan to mitigate such calls. |
|
| Unsolicited Telefacsimile Messages Act |
Do not initiate an unsolicited fax that promotes goods or services for purchase to a recipient with whom you have no prior contractual or business relationship. Do not send an unsolicited fax to a recipient you knew or reasonably should have known is a government entity, even one with which you have a prior contractual or business relationship. |
Biometric privacy
33 laws, 32 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Protection of Personal Data, biometric data provisions |
An app that captures or stores a voiceprint, faceprint, or other biometric identifier from a person in Armenia must obtain the data subject's consent, unless a law-defined purpose can only be achieved through that processing, and must notify the authorized body before beginning to process biometric data, since Armenia's biometric-data definition does not distinguish by modality or by whether the identifier was derived from a recording. |
|
| Law on Personal Data, biometric data enumeration and general processing conditions |
An app that captures or stores a facial image, voiceprint (sound fragment and its acoustic parameters in the Act's own term), or other biometric identifier from a person in Azerbaijan is still bound by this Act's ordinary processing conditions, a lawful basis under Art. 9.6 and destruction under Art. 9.4 once the purpose is achieved, even though Azerbaijan does not treat biometric data as a heightened special category and imposes no biometric-specific consent, retention, or storage-technology duty. |
|
| Act of 30 July 2018 Article 9 and GBA/APD Biometric Recommendation and Enforcement |
Do not rely on employee consent as the legal basis for a workplace biometric time-registration or access system in Belgium; the Litigation Chamber fined an employer 45,000 EUR for exactly this in Decision 114/2024. |
|
| Law on the Protection of Personal Data of Bosnia and Herzegovina, biometric data processing |
Obtain the person's explicit consent before processing a biometric identifier for the individual secure identification of a service user, and only where the processing is otherwise required by law or necessary to protect a person, property, classified information, or a trade secret, and the person's conflicting interests do not prevail, under Article 57a. Obtain an employee's explicit consent before processing their biometric data to record working time or to control entry to and exit from official premises, and offer it only where required by law or as an alternative to another recording or access method, under Article 57b. |
|
| Provisions on Security Management of Facial Recognition Technology Application |
These duties bind the deployment and use of facial recognition; Article 2 exempts facial-recognition R&D and algorithm-training activities from the Measures. Obtain separate, explicit, informed, voluntary consent before collecting or using facial recognition data, with guardian consent for anyone under 14, and use the method with the least impact on individual rights available. Do not install facial recognition devices inside hotel rooms, public bathhouses, public changing rooms, or public restrooms. |
|
| HB 24-1130, Privacy of Biometric Identifiers and Data |
Before collecting a Colorado resident's biometric identifier such as a fingerprint, voiceprint, or facial geometry template, disclose in a clear and accessible manner what is collected, why, and how long it will be kept, and obtain the consumer's consent, whatever your app's overall personal-data processing volume. Do not sell, lease, or trade a biometric identifier, or disclose one to a third party, without the consumer's consent or a listed statutory exception. |
|
| Croatian Act Articles 21-23, Biometric Data by Sector |
Obtain the data subject's explicit GDPR-compliant consent before processing biometric data of a person in Croatia for the individual, secure identification of a service user, per Act Article 22(2). Offer a non-biometric alternative and obtain explicit consent, or rely on a legal prescription, before deploying employee biometric time-and-attendance or access-control processing in Croatia, per Act Article 23. |
|
| GDPR Article 9 and Law 125(I)/2018, Genetic and Biometric Data in Cyprus |
Do not process genetic or biometric data of a person in Cyprus for life or health insurance purposes, per Law 125(I)/2018's insurance prohibition. Obtain separate, specific consent, over and above the ordinary GDPR consent standard, before relying on consent as the lawful basis for processing genetic or biometric data of a person in Cyprus. |
|
| CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001) |
Do not rely on employee consent alone as the legal basis for a workplace biometric system; use a legal-obligation or legitimate-interest basis, or pair consent with a genuinely equivalent non-biometric alternative. |
|
| Law on Personal Data Protection, biometric data article |
An app that captures or stores a facial image, voiceprint, or other biometric identifier from a person in Georgia must have a necessity-based purpose recognized by Art. 9 or the data subject's consent, and must determine in writing, before processing begins, the purpose, volume, storage period, and destruction procedure for that biometric data. |
Show the other 23 laws
| GDPR Article 9 and Law 4624/2019, Special Categories in Greece |
Ground the processing of any biometric identifier of a person in Greece, including a faceprint or voiceprint captured for unique identification, on a GDPR Article 9(2) condition such as explicit consent, unless the processing falls within Law 4624/2019's social-security or employment-fitness derogation for grouped genetic, biometric, and health data. |
|
| Biometric Information Privacy Act (BIPA) |
Obtain a written release, including informed consent or an accepted electronic signature, before collecting or capturing any retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, after disclosing in writing the specific purpose and length of time the data will be collected, stored, and used. Never sell, lease, trade, or otherwise profit from a biometric identifier or biometric information, and disclose it only with consent, for a transaction the subject requested, or as required by law or a valid warrant or subpoena. |
|
| Law on Personal Data Protection, biometric data definition |
An app that derives a faceprint, voiceprint, or other biometric identifier from an individual in Indonesia must treat it as specific personal data under Article 4 and obtain the stricter consent Article 21 requires for that category. |
|
| Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions |
Do not scrape or process publicly posted facial images to build a biometric identification database without a valid GDPR Article 9 basis; the Garante fined Clearview AI EUR 20 million for exactly that and banned further collection. |
|
| Act on the Protection of Personal Information, individual identification code and biometric provisions |
An app that derives a faceprint, voiceprint, or other individual identification code from a person in Japan, including one derived from a photo, video, or audio recording, must give purpose-of-use notice and avoid wrongful acquisition under APPI's general rules, and must obtain the data subject's consent before disclosing the identifier to a third party. |
|
| Act on the Protection of Personal Information, Specific Biometric Personal Information from a date not yet set |
An app that handles a data subject's Specific Biometric Personal Information, an individual identification code converted from a bodily feature obtainable without special technology or great expense and of a kind the data subject cannot easily recognize is being captured, must, except in specified cases, notify the data subject in advance or place the purpose of use where the data subject can readily learn it; may not provide it to a third party under the ordinary opt-out mechanism; and must, on the data subject's request, cease using it or stop providing it to a third party without delay, unless a specified exception applies. |
|
| Law on Personal Data and Their Protection, biometric data provisions |
An app is not exempt from Kazakhstan's Law on Personal Data merely because biometric data has no dedicated definition in the Act. Collecting biometric data in a public place for identification purposes is restricted to constitutional-order, public-order, rights, health, or morality grounds unless the subject consents, and biometric data stored on Kazakhstani subjects must sit in a database located inside Kazakhstan like any other personal data. Confidentiality of biometric data specifically is deferred to other Kazakh legislation, which the Act does not name and which is not identified here. |
|
| Law No. 06/L-082 on Protection of Personal Data, use of biometric characteristics |
In the public sector, use biometric characteristics only where strictly necessary for the safety of individuals, the protection of property, or safeguarding confidential data and trade secrets, and only where no easier means would achieve that purpose. In the private sector, apply the same necessity test, inform employees in writing in advance of the measures and their rights, and submit a detailed description of the proposed measures to the Agency for Information and Privacy before taking them. |
|
| Personal Data Protection Act, biometric data definition and sensitive category |
An app that collects or processes a faceprint, voiceprint, or other biometric identifier from an individual in Malaysia, including one derived from technical processing of a photo, video, or audio recording, must obtain the data subject's explicit consent under Act 709's sensitive personal data standard. |
|
| GDPR Article 9 and Cap. 586, Genetic, Biometric and Health Data Research Processing in Malta |
Ground the processing of any biometric identifier captured for commercial authentication or identification purposes on a GDPR Article 9(2) condition such as explicit consent; Cap. 586's research-specific duty does not reach this use case. |
|
| Law on Personal Data Protection, biometric measures from a date not yet set |
Perform biometric measures, meaning the establishment and comparison of personal traits to establish or prove an individual's identity, only in accordance with this law, under Article 31. Confine a biometric measure in the public sector to entry into business or official premises and presence at work of employees, provided for by law, and only where the aim cannot be achieved another way, under Article 32. |
|
| UAVG Article 29, Biometric-Data Exception for Authentication or Security |
Rely only on an authentication-or-security purpose, or another GDPR Article 9(2) basis, before processing biometric data of a person in the Netherlands for unique identification; UAVG Article 29's exception reaches no broader purpose on its face. |
|
| New York City | Biometric Identifier Information Law |
A commercial establishment operating in New York City that collects, retains, converts, stores, or shares a customer's biometric identifier information must post a clear and conspicuous sign at every customer entrance disclosing that practice, and must never sell, lease, trade, or otherwise profit from transacting in biometric identifier information regardless of signage. |
| GDPR Article 9, Act Article 107(2), and Kodeks Pracy Article 22(1b), Biometric Data |
Obtain an explicit GDPR Article 9(2) legal basis before processing biometric data of a person in Poland; unlawful processing of biometric data carries a raised criminal penalty ceiling under Act Article 107(2). Limit an employer's no-consent biometric processing of a Polish employee to controlling access to particularly sensitive information or specially protected premises, and restrict access to authorized, confidentiality-bound staff, per Kodeks pracy Article 22(1b). |
|
| Portland | Prohibit the Use of Face Recognition Technologies by Private Entities in Places of Public Accommodation |
Inside Portland, a product built for or offered to a place of public accommodation must not use face recognition technology to identify, verify, detect, or characterize an individual's facial features, unless the use falls within the ordinance's exceptions for legal compliance, an individual unlocking their own device, or automatic face detection inside a social media application. |
| Federal Law No. 572-FZ, Unified Biometric System for Identification and Authentication |
Route biometric identification, matching an unknown person against a database, of a person in Russia only through the state Unified Biometric System; a private accredited system may only perform authentication, using derived mathematical vectors rather than the original template, and may not transmit those vectors to a third party. Obtain written consent before processing a person's biometric data in Russia, never condition service on that consent, and retain any biometric sample your organization holds only up to 10 days before deleting it, since the durable copy of record lives in the state system. |
|
| ZVOP-2 Chapter 4 (Articles 81-84) and Article 80, Biometric and Genetic Data |
Treat biometric-data processing in Slovenia as prohibited by default under ZVOP-2 Article 81 unless another Slovenian law both authorizes it and sets its conditions of use; a bare GDPR Article 9(2) basis alone is not sufficient in this jurisdiction. Do not deploy automated license-plate recognition or a biometric-recognition system on a public surface in Slovenia; ZVOP-2 Article 80 bans this outright, with fines up to EUR 30,000 under Article 105. |
|
| GDPR Article 9, Dataskyddslagen Chapter 3, and the IMY Skelleftea Facial-Recognition Decision |
Do not deploy a facial-recognition or fingerprint attendance-tracking system for a person in Sweden on consent alone; IMY treats employer consent as generally invalid given the employment power imbalance and fined the Skelleftea school board for exactly this processing. Obtain a GDPR Article 9(2) basis, and expect weighty grounds plus a data protection impact assessment to be required, before deploying a biometric identification system in Sweden. |
|
| Law on the Protection of Personal Data, biometric personal data |
An app that processes a faceprint, voiceprint, or other biometric identifier of a Tajikistani data subject for identification purposes must obtain the subject's written consent, unless the processing falls within a justice, security, or law-enforcement exception. Confidentiality of biometric data specifically is deferred to other Tajik legislation, which the Act does not name and which is not identified here. |
|
| Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149 |
Inform an individual and obtain consent before capturing their retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry for a commercial purpose in Texas. Do not sell, lease, or disclose a captured biometric identifier except for the narrow statutory exceptions covering identification of a missing or deceased person, a requested financial transaction, legal compulsion, or a law enforcement warrant. |
|
| Ley N° 18.331, biometric data |
Process biometric data only within a lawful basis under article 9 of Ley N° 18.331 (typically the data subject's free, prior, express, and informed consent), since biometric data is not exempt from that consent framework. |
|
| Law on Personal Data, biometric and genetic data |
An app that processes a faceprint, voiceprint, or other biometric or genetic identifier of an Uzbek data subject for identification purposes must obtain the subject's consent, subject to narrow statutory exceptions for treaty implementation, administration of justice, or enforcement proceedings. Electronic biometric or genetic data stored outside an information system must be kept on media that exclude unauthorized access. |
|
| HB 1493, Biometric Privacy Law |
Provide notice, obtain consent, or provide a mechanism to prevent use, before enrolling a biometric identifier such as a voiceprint or faceprint in a database for a commercial purpose. This duty does not reach an identifier generated from a photo, video, or audio recording. |
Data subject rights
27 laws, 27 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law of the Republic of Belarus On Personal Data Protection, rights of the personal data subject |
Let a personal data subject withdraw consent at any time without giving reasons, and within fifteen days of that withdrawal stop processing, erase the data and notify the subject, or, where erasure is not technically possible, restrict further processing and notify the subject instead, under Article 10. |
|
| Personal Data Protection Law, rights of the data subject |
Obtain a person's prior consent before sending them unsolicited direct marketing communications of any kind, tell them before their data is first used for that purpose or disclosed to a third party, and let them withdraw consent at any time. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, droits liés au traitement |
Get a person's prior consent before contacting them with direct marketing by phone, fax, SMS, email, instant message, or social network, and let them unsubscribe or change their preferences at any time. |
|
| GDPR Article 22 and Law 125(I)/2018 Article 31, Decisions About a Person in Cyprus |
Do not use personal data you process for archiving in the public interest, scientific or historical research, or statistics to take a decision that produces legal effects for a person in Cyprus or similarly significantly affects them, under Law 125(I)/2018 Article 31. |
|
| Ley para la Protección de Datos Personales, rights of data subjects |
Tell a data subject, before you collect their data, its purpose, its recipients, the database it will sit in, how to reach you and your delegate, the content of their ARCO-POL rights, and the security measures you keep; get a fresh authorization if you later plan a different purpose. |
|
| GDPR Article 22, Automated Individual Decision-Making |
Do not base such a decision on special category data under Article 9(1) unless the data subject gave explicit consent or the processing serves a substantial public interest, with suitable safeguards in place. |
|
| Law No. 025/2023, rights of the data subject and transparency obligations |
Before accessing or storing information on a subscriber's or user's terminal equipment, such as through a cookie, tell them the purpose and how to object, and proceed only once they have consented, except where the access is strictly necessary to provide an electronic communication service they expressly requested. |
|
| Data Protection Act, rights of data subjects |
Do not provide, use, obtain, or procure a data subject's personal data for direct marketing without their prior written consent, and stop on their written request at any time. |
|
| Data Protection Act, 2020, rights of data subjects |
Do not process personal data for direct marketing unless the data subject consents or is your customer, and do not approach the same data subject for that consent more than once. |
|
| Law No. 81/2018, Part V, notice, objection, access and correction |
Mark an online promotional advertisement as a promotional advertisement and name the person it was placed for, send no unsolicited marketing email to a real person's name and address without their consent unless you obtained the address lawfully through a previous engagement with them, and put in every marketing email a reply address through which the recipient can ask to stop receiving them permanently and free of charge. |
Show the other 17 laws
| Law No. 6 of 2022, notice, access and objection rights over personal data |
Do not process personal data where doing so causes harm to, or infringes the rights or freedoms of, the person it was collected from. Do not use a person's data for a purpose other than the one they agreed to without obtaining their consent. |
|
| Data Protection Act 2017, automated individual decision making |
Do not base a decision producing a legal or similarly significant effect on a data subject solely on automated processing, including profiling, unless a listed exception (contractual necessity, a safeguarded legal authorisation, or the data subject's explicit consent) applies. Do not base automated processing intended to evaluate personal aspects of an individual on special categories of personal data. |
|
| Law No. 09-08, rights of the data subject |
Do not send direct marketing by automated call, fax, or electronic mail to anyone who has not given prior consent, and, for the narrow email exception the law allows to existing customers, always let the recipient opt out, free of charge, of further messages. |
|
| Ley No. 787, Ley de Protección de Datos Personales, rights of data subjects |
Include personal data in a file built for advertising, promotions, offers, or direct sale only with the data subject's consent or from a publicly accessible source, give the data subject free access to it, and let them request removal from it at any time. Do not send electronic advertising to a person who has expressly stated they do not want to receive it, offer every recipient of an electronic advertisement the means to refuse further advertising or revoke consent, and keep a contract proving the personal data you use for marketing were obtained with consent or from a public access source. |
|
| Loi n° 2022-59, droits des personnes concernées |
Do not use a person's data for direct marketing without their prior consent, and stop processing their data for direct marketing, free of charge, as soon as they object, telling them of that right before you first use or disclose their data for that purpose. |
|
| Oregon Consumer Privacy Act, consumer rights |
Respond to a consumer rights request without undue delay and within 45 days of receipt, decide an appeal within 45 days, and honor a consent revocation within 15 days. |
|
| Law No. 29-2019, rights of the data subject |
Let a minor consent alone to processing of their personal data for an information-society service from age sixteen; below that age, take consent jointly from the minor and the holder or holders of parental authority, and write the information addressed to the minor in clear, simple terms. |
|
| Federal Law No. 152-FZ, Article 16, Decisions Based Solely on Automated Processing |
Do not make a decision that produces legal consequences for a Russian data subject, or otherwise affects their rights and legitimate interests, solely on the basis of automated processing of their personal data, unless they consented in writing or a federal law that protects their rights provides for it. |
|
| Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, droits de la personne concernée |
Do not send a person direct-marketing communications using their personal data unless they have first expressed consent to receive them. |
|
| Data Protection Act, 2023, information to the data subject and rights of the data subject |
Let a data subject withdraw consent as easily as they gave it, and tell them what withdrawing means. |
|
| Protection of Personal Information Act, rights of data subjects |
Do not process personal information for direct marketing by electronic communication unless the data subject has consented, or is an existing customer given a free and simple chance to opt out at collection and on every marketing contact afterward. |
|
| Law No. 12 of 2024 on Protection of Electronic Personal Data, rights of data subjects and electronic marketing |
Do not process, disclose or divulge personal data without the data subject's explicit consent, unless a legally authorized case applies. Obtain a data subject's consent, identify yourself as sender, give a correct return address, and label the message as direct marketing before sending any electronic marketing contact, and give the data subject a clear and easy way to refuse it or withdraw consent. +1 more |
|
| Loi n° 2019-014, droits de la personne concernée |
Do not send unsolicited direct marketing to a person using their personal data without their prior consent to receive it. |
|
| Organic Act on the Protection of Personal Data, rights of the data subject |
Obtain the person's express, written consent before processing their personal data, and let them withdraw that consent at any time. Do not rely on a consent given for one form or purpose of processing to cover a different form or purpose, and do not process personal data for advertising without the person's separate, express consent. |
|
| Children's Online Privacy Protection Rule (COPPA), including 2025 biometric identifier amendments |
Obtain verifiable parental consent before collecting, using, or disclosing a child's personal information, including biometric identifiers such as voiceprints or facial templates. |
|
| Law on Personal Data, data subject rights |
An app must let an Uzbek data subject learn whether their data is held and processed, obtain information on access conditions, consent to or withdraw from inclusion in public sources, and suspend processing on request where the data is incomplete, outdated, or unreliable. |
|
| Data Protection Act, 2021, automated decisions |
Where an automated decision rests on a contract, a written law or explicit consent, put suitable safeguards in place, including the right to obtain human intervention, to put a point of view and to contest the decision, and do not process sensitive personal data automatically at all unless the data subject expressly consented, the processing is in the public interest, or a written law permits it with safeguards. |
Interception and recording consent
26 laws, 23 places| Place | Law | What it asks, as read here |
|---|---|---|
| Telecommunications (Interception and Access) Act 1979, Prohibition on Interception and Civil Remedies |
Do not intercept, authorise or permit another person to intercept, or do anything that would enable interception of, a communication passing over a telecommunications system. |
|
| California Invasion of Privacy Act, Recording and Interception of Communications |
Do not tap or make an unauthorized connection with a telephone or telegraph wire, line, cable, or internal telephonic communication system, or learn or try to learn the contents of a message while it is in transit, without the consent of all parties or other authorization. Get the consent of every party before using an electronic amplifying or recording device to eavesdrop on or record a confidential communication, whether the parties are in each other's presence or on a call; a communication is confidential where a party has an objectively reasonable expectation it is not being overheard or recorded, and disclosing that you are listening or recording, so that every party knows it, takes the recording outside this duty. +2 more |
|
| Criminal Code, Interception of Private Communications |
Get the consent, express or implied, of the originator of a private communication or of the person the originator intended to receive it, before intercepting it by an electro-magnetic, acoustic, mechanical or other device; consent from either one of those two people is enough under federal law, so a business recording its own calls is not committing this offence. Before a recording or transcription vendor intercepts a call for you, give it your consent as a party to the call: the exemption covers any person who has a party's consent, not only the party. +1 more |
|
| Connecticut Action for Illegal Recording of Private Telephonic Communications |
Before using an instrument, device or equipment to record an oral private telephonic communication, either obtain the consent of all parties to it in writing or as part of, and at the start of, the recording, or give verbal notification recorded at the beginning and made part of the communication, or use an automatic tone-warning device that produces a distinct signal repeated at approximately fifteen-second intervals throughout the call. This duty reaches a party to the call who records it, not only a third party, and Connecticut carries no general exception letting a business record its own customer, sales or support calls without using one of these three mechanisms. |
|
| Connecticut Wiretapping, Tampering with Private Communications and Eavesdropping |
As a person who is not a sender or receiver of a telephonic, telegraphic or cellular radio telephone communication, do not intentionally overhear or record it by instrument, device or equipment when neither the sender nor the receiver has consented; this wiretapping offense does not reach a party to the communication who records it. As a person not present at a conversation or discussion, do not intentionally overhear or record it by instrument, device or equipment when no party to it has consented; this mechanical-overhearing offense does not reach a participant in the conversation. +2 more |
|
| Delaware Violation of Privacy Statute (Surveillance and Interception Clauses) |
Do not trespass on property intending to subject anyone to eavesdropping or other surveillance in a private place. Do not install, in a private place, a device for observing, photographing, recording, amplifying or broadcasting sounds or events there, without the consent of the person or persons entitled to privacy there. +3 more |
|
| Delaware Wiretapping, Electronic Surveillance and Interception of Communications Statute |
Do not intercept, or endeavor or procure another to intercept, a wire, oral or electronic communication unless you are a party to it or one of the parties has given prior consent, and never for the purpose of a criminal or tortious act; one party's consent is enough under this chapter. Do not intentionally disclose or use the contents of a wire, oral or electronic communication that you know, or have reason to know, were obtained by an interception made in violation of this chapter. +1 more |
|
| ePrivacy Directive |
Do not listen to, tap, store, or otherwise intercept or monitor the content or related traffic data of a communication carried over a public electronic communications network without the consent of the users concerned, unless a Member State has authorised it under Article 15(1) for national security, defence, public security, or the investigation and prosecution of crime. |
|
| Florida Security of Communications Act, Interception and Civil Remedies |
Get the prior consent of every party to a wire, oral, or electronic communication before intercepting, recording, or disclosing its contents; consent from only one party, including yourself as a party to the call, is not enough under Florida law. |
|
| Strafgesetzbuch, Violation of the Confidentiality of the Spoken Word |
Do not record the non-public spoken word of another person on a sound-recording device without that person's authorization, and do not use or share a recording made without it. This reaches a party to the conversation: do not record the other side of your own call or meeting without authorization, even though the words were addressed to you. +2 more |
Show the other 16 laws
| Illinois Eavesdropping Article, Interception and Civil Remedies (720 ILCS 5/14-2 as rewritten by Public Act 98-1142) |
Do not surreptitiously record or transmit a private conversation, including one you take part in, without the consent of every other party. Do not surreptitiously intercept, record or transcribe a private electronic communication to which you are not a party without the consent of every party. +2 more |
|
| Irish ePrivacy Regulations |
Do not listen to, tap, store, or otherwise intercept or monitor the content or related traffic data of a communication without the consent of the users concerned, unless a legally authorised exception for national security, defence, public security, or the investigation and prosecution of crime applies. |
|
| Postal and Telecommunications Services Act 1983, Prohibition on Interception of Telecommunications Messages |
Do not listen to, or record by any means, a telecommunications message in the course of its transmission unless either the person on whose behalf the message is sent or the person intended to receive it has consented to the listening or recording. Do not disclose the existence, substance or content of a message you know was intercepted without that consent, or use any information obtained from it. |
|
| Maryland Wiretap and Electronic Surveillance Act |
Do not intercept a wire, oral, or electronic communication, including one you take part in, unless every party has given prior consent or another exception in the subtitle applies; your own consent as a participant is not enough. Do not disclose or use the contents of a communication you know or have reason to know was intercepted in violation of the subtitle. +1 more |
|
| Interception of Wire and Oral Communications |
Obtain the prior authorization of every party to a wire or oral communication before secretly hearing, recording, or transmitting its contents, or aiding another to do so, with any device; a recording made openly, with the parties aware it is happening, is not restricted by this duty, because the statute's own definition of an interception requires secrecy. Do not disclose or use the contents of a wire or oral communication, or aid another to do so, knowing it was obtained through an unlawful interception. |
|
| Eavesdropping, Prohibition and Civil Remedies |
Get the consent of every party to a private conversation before using a device to overhear, record, amplify or transmit any part of it; the chapter defines eavesdropping by the private discourse of others and does not say whether a party recording their own conversation is covered. Do not use or divulge information you know or reasonably should know was obtained by eavesdropping in violation of the chapter. |
|
| Nevada Interception, Eavesdropping and Disclosure of Communications Statute |
Do not intercept a telephone call or other wire communication, which includes writing, signals and pictures sent by wire or cable, on one party's consent alone; the section permits it only with one party's prior consent together with an emergency that makes a court order impractical, followed by an application for a judge's ratification within 72 hours. Do not surreptitiously listen to, monitor or record a private conversation of other persons with a listening device unless one of the persons engaged in it authorizes you. +1 more |
|
| New Hampshire Wiretapping and Eavesdropping Act, Interception and Civil Damages |
Do not intercept, disclose or use the contents of a telecommunication or oral communication without the consent of every party to it. Being a party to the conversation, or holding only one other party's prior consent, does not excuse you: knowingly intercepting a telecommunication or oral communication that way is itself an offense, and the chapter has no exception for a business recording its own sales or customer-service calls. |
|
| Security of Communications Act, prohibited interception and consent exceptions |
Do not intercept, disclose, or use the contents of a wire, oral, or electronic communication unless you are a party to it or one of the parties has given prior consent, and, if you are not acting under color of law, do not rely on that consent where the interception is for the purpose of committing a criminal act. Do not disclose or use the contents of a wire, oral, or electronic communication, or evidence derived from it, knowing or having reason to know it was obtained through an unlawful interception. |
|
| Oregon Obtaining and Interception of Communications Statute |
Do not obtain, or attempt to obtain, the whole or any part of a telecommunication or radio communication to which you are not a participant, unless at least one participant has consented. Do not obtain a conversation, telecommunication or radio communication from another person while knowing or having good reason to believe it was first obtained in a way the section prohibits, and do not use or divulge one obtained by prohibited means, unless you took no part in first obtaining it and it concerns a matter of public concern. |
|
| Wiretapping and Electronic Surveillance Control Act, Interception, Consent Exception and Civil Action |
Do not intercept, disclose or use the contents of a wire, electronic or oral communication unless every party has given prior consent or another exception in section 5704 applies; outside law enforcement, being a party to the communication is not an exception. If your website loads a third-party script that routes a visitor's communications to the vendor's servers, get the visitor's prior consent; it is no defense that the visitor communicated directly with those servers, and consent may be implied only where the visitor knew or should have known of the interception. +1 more |
|
| Unlawful Interception of Communications and Civil Remedy |
Do not intercept, or procure another to intercept, a wire, oral or electronic communication unless you are a party to it or one of its parties has given prior consent, and never for the purpose of committing an unlawful act; one party's consent is enough. Do not disclose the contents of a communication you know or have reason to know were obtained by unlawful interception, and do not use contents you know, or are reckless about whether, were obtained that way. +1 more |
|
| Investigatory Powers Act 2016, Unlawful Interception and Lawful Business Monitoring |
Do not intentionally intercept, or procure another person to intercept, a communication in the course of its transmission by a telecommunication system or a public postal service in the United Kingdom unless you have lawful authority to do so. Before you make the content of a call or message available to anyone who is neither its sender nor its intended recipient, a recording, transcription or monitoring vendor included, get the consent of both the sender and the intended recipient or rely on the business-monitoring authority below; recording a call you are a party to, for your own use, is not interception. +1 more |
|
| Wiretap Act |
Get the consent of at least one party to a wire, oral, or electronic communication before intercepting, recording, transcribing, or disclosing its contents; consent from a person who is themselves a party to the call is enough under federal law even without the other party's knowledge, unless the interception is for the purpose of committing a crime or a tort. |
|
| Virginia Wiretapping, Eavesdropping and Disclosure of Communications Statute |
Do not intentionally intercept a wire, electronic or oral communication, or have someone else intercept one, unless you are a party to it or one of its parties has given prior consent; one party's consent is enough. Do not intentionally disclose or use the contents of a wire, electronic or oral communication you know, or have reason to know, was obtained through interception. +1 more |
|
| Privacy Act, Recording and Interception of Private Communications |
Obtain the consent of every participant to a private telephone, radio, or other transmitted communication, and every person engaged in a private conversation, before recording or intercepting it by any device; consent is established when one party announces to all the others, in a reasonably effective manner, that the recording or transmission is about to happen, provided the announcement is itself recorded. Do not read or answer a private message sent to someone else, on the device it was sent to, before that person has seen it, without the consent this chapter requires; the Washington Supreme Court has held that doing so is an interception even though the message has already arrived. |
Enforcement supervision
22 laws, 22 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law on the Protection of Personal Data, enforcement and supervision |
Do not access personal data whose access is barred to you without authorisation, on pain of six months' to two years' imprisonment or a corresponding fine, aggravated where achieved by defeating security rules or for a benefit. Do not erase, destroy, damage, suppress or modify personal data without due authorisation, on pain of eighteen months' to three years' imprisonment or a corresponding fine, aggravated for particularly serious damage. |
|
| Data Protection Act, 2013, information commissioner and enforcement |
Do not intentionally disclose personal information of another person in contravention of this Act, and do not collect, store or dispose of personal information in a manner that contravenes it, each a criminal offence. |
|
| Ley 25.326, enforcement, sanctions, and the habeas data action |
Do not access a personal database without authorization, disclose personal data you are bound to keep secret, or insert data into a personal-data file illegitimately; a heavier penalty applies when the conduct reaches a genetic-data databank or DNA registry. |
|
| Data Protection Act 2003, Commissioner, enforcement and penalties |
Do not disclose personal data processed on behalf of a data controller without that controller's prior authority. Do not obtain access to, or disclose, personal data without the authority of the data controller or data processor who holds it. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, Autorité de Protection des Données Personnelles, sanctions et infractions pénales |
Include an unsubscribe link in every unsolicited electronic message you send based on personal data you collected, and do not use another person's or entity's identity to deceive message recipients or website users into disclosing personal or confidential data. |
|
| Personal Information Protection Act 2016, Commissioner, enforcement and offences |
Do not contravene the sensitive personal information restriction, and do not dispose of, alter, falsify, conceal or destroy evidence during a Commissioner investigation or inquiry. |
|
| Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision |
Do not access personal data barred to you without due authorisation, on pain of up to one year's imprisonment or a fine of up to 120 days, doubled where achieved by defeating security rules or for a benefit. Do not erase, destroy, damage or alter personal data without authorisation, on pain of up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage. |
|
| Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, article 74 (atteinte à la vie privée et traitement illicite des données à caractère personnel) |
Do not record, fix, or transmit another person's private or confidential electronic data without their consent, and do not intercept personal data while it is in transit between information systems. Do not collect a person's nominative data by unlawful means in order to harm their privacy or standing. +2 more |
|
| Código Penal, artículo 196 bis, Violación de datos personales |
Do not appropriate, copy, transmit, publish, or otherwise give unauthorized treatment to a person's data or images without their authorization, since doing so for one's own or a third party's benefit, to the danger or harm of that person's privacy, is a criminal offense. |
|
| Ley para la Protección de Datos Personales, enforcement and sanctions |
Carry the burden of proving that you obtained consent or delivered the privacy notice, and, for an international transfer, that the transfer was lawful. Do not process personal data without prior consent, deny an ARCO-POL request, use a child's data without parental consent, reverse a pseudonymization, or use, transfer, share or commercialize personal data in violation of this Law. |
Show the other 12 laws
| Penal Code of the State of Eritrea, Violation of Privacy from a date not yet set |
Do not intentionally intercept, open, or otherwise interfere with a telephone call, letter, electronic message, or other private communication addressed to another person, without lawful authority. If facts from a communication not addressed to you come to your attention by mistake, inadvertence, or negligence, do not divulge those facts or derive a gain from them. |
|
| Personal Data Protection and Privacy Act, 2025, the Information Commission, offences and penalties from a date not yet set |
Do not sell personal data, and do not process personal data unlawfully for financial gain or to cause harm: both are criminal offences under the Act. |
|
| Data Protection Act, enforcement, offences and penalties |
Do not purchase, knowingly obtain, or knowingly or recklessly disclose another person's personal data, and do not sell or offer to sell personal data. |
|
| Código Penal, acceso no autorizado a datos personales (descubrimiento y revelación de secretos) |
Do not access, appropriate, alter or use another person's personal data held in a file, register or database, public or private, without authorization and to their detriment. Do not access another person's documents, papers or communications, or intercept their telecommunications, to learn their secrets or violate their privacy without their consent. |
|
| Data Protection Act, 2020, the Information Commissioner, penalties and compensation |
Do not knowingly or recklessly obtain, disclose or procure the disclosure of personal data without the consent of the data controller concerned, and do not sell or offer to sell personal data obtained that way. |
|
| Criminal Code 2011, Violation of Privacy (unlawful eavesdropping, surveillance, and breach of privacy of messages) |
Do not trespass on property, or install a hidden device, with intent to eavesdrop on, observe, photograph, or record sounds or events in a private place, without the consent of the person entitled to privacy there. Do not install or use, outside a private place, a device that hears, records, amplifies, or broadcasts sounds originating in that place that would not ordinarily be audible or comprehensible outside, without the consent of the person entitled to privacy there. +2 more |
|
| Código Penal de Puerto Rico, delitos contra el derecho a la intimidad (unauthorized use and disclosure of personal data records) |
Do not access, use, modify, or disclose another person's or another company's reserved personal or family data without authorization; doing so is a felony under Puerto Rico's Penal Code, independent of any separate civil privacy duty. |
|
| Data Protection Act, 2018, Information Commissioner, enforcement and offences from a date not yet set |
Do not wilfully disclose personal information in contravention of the Act, or collect, store, or dispose of personal information in a manner that contravenes the Act. |
|
| San Marino Law No. 171, the Data Protection Authority, remedies and fines |
Do not publish or disseminate news or images identifying a child involved in legal proceedings. |
|
| Data Protection and Privacy Act, 2019, enforcement and offences |
Do not unlawfully obtain, disclose, destroy, delete, mislead, conceal, alter, sell or offer to sell personal data, on pain of a fine of two hundred and forty to two hundred and forty five currency points or imprisonment of up to ten years, or both. |
|
| FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement) |
Do not engage in unfair or deceptive practices when collecting, using, or sharing personal data. |
|
| Ley Especial contra los Delitos Informáticos, privacy of personal data and communications (Arts. 20-22) |
Do not appropriate, use, modify, or delete a person's personal data or information held in a computer system without their consent. Do not access, intercept, or reproduce a person's private data message, transmission, or communication signal without authorization. +1 more |
Device storage and tracking consent
18 laws, 17 places| Place | Law | What it asks, as read here |
|---|---|---|
| Invasion of Privacy Act, Pen Registers and Trap and Trace Devices |
Do not install or use a pen register or a trap and trace device without first obtaining a court order, unless you are a provider of electronic or wire communication service using the device to operate, maintain, or test your own service, to protect your rights or property, to protect users from unlawful or abusive use of the service, to record that a communication was initiated or completed in order to guard against fraudulent, unlawful, or abusive use, or unless the user of the service has consented. |
|
| Canada's Anti-Spam Legislation |
Get the express consent of the computer system's owner or an authorized user before installing, or causing to be installed, a computer program on that system in the course of a commercial activity, and before causing an electronic message to be sent from a system on which you installed a program this way. If the program collects personal information stored on the system, interferes with the owner's or user's control of the system, changes or interferes with settings or data without their knowledge, causes the system to communicate with another device without authorization, or can be activated by a third party without the owner's or user's knowledge, describe those material elements and their impact clearly, prominently and separately from the licence agreement when requesting consent, and obtain a written acknowledgement that the person understands and agrees. |
|
| Delaware Pen Register and Trap and Trace Device Statute |
Do not install or use a pen register or a trap and trace device without first obtaining a court order under 11 Del. C. § 2433, unless you are a provider of wire or electronic communication service using one to operate, maintain or test your own service, to protect your rights, property or users from abuse or unlawful use, to record that a communication was initiated or completed to protect yourself, another provider, or a user from fraudulent, unlawful or abusive use, or with the consent of the user of that service; a device a provider or its customer uses for billing, or for cost accounting in the ordinary course of business, is not a pen register. |
|
| Cookie Directive |
Obtain the user's or subscriber's consent, after giving them clear and comprehensive information about the purposes of the processing, before storing information on their device or accessing information already stored there (cookies, local storage, device fingerprinting, or any comparable technique), whether or not that information is personal data. |
|
| Florida Security of Communications Act, Pen Register and Trap and Trace Device Prohibition |
Whoever you are, and not only if you are an investigative or law enforcement officer, do not install or use a pen register or a trap and trace device, a device that records the dialing, routing, addressing, or signaling information of a wire or electronic communication without capturing its contents, without first obtaining a court order, unless the user of the service being monitored has consented, or the use is by the service provider itself for network operation or for protecting the provider or a user from fraudulent or unlawful use of the service. |
|
| Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, Protection of Privacy in Terminal Equipment |
Obtain the end user's consent, given on the basis of clear and comprehensive information and in the manner the GDPR requires, before storing information on the end user's terminal equipment or accessing information already stored there. |
|
| Irish ePrivacy Regulations |
Obtain the user's or subscriber's consent, after giving them clear and comprehensive information, prominently displayed and easily accessible, about the purposes of the processing, before storing information on their device or accessing information already stored there (cookies, local storage, or a comparable technique). |
|
| Maryland Pen Register and Trap and Trace Device Act |
Do not install or use a pen register or a trap and trace device, a device or process that records the dialing, routing, addressing, or signaling information of a wire or electronic communication without capturing its contents, without first obtaining a court order, unless you are a provider of the communication service using it to operate, maintain, or test the service, to protect the provider or its users from abuse, fraud, or unlawful use, or with the consent of the user of that service. |
|
| Limitations on Use of Pen Register or Trap and Trace Device |
Do not install or use a pen register or a trap and trace device, a device that records or decodes the number dialed or the originating number of a wire or electronic communication, without a court order, unless you are the provider of the communication service using it to operate, maintain, test or protect the service or its users, to guard against fraud, or with the consent of each person whose number is recorded or decoded. Do not use a pen register or trap and trace device that has the ability to record conversations. |
|
| Nevada Pen Register and Trap and Trace Device Prohibition |
Do not install or use a pen register or trap and trace device without first obtaining an order from a Nevada district court, except as the federal pen register and trap and trace statute otherwise provides. |
Show the other 8 laws
| New Hampshire Pen Register and Trap and Trace Devices Act |
Do not install or use a pen register or trap and trace device, a device that captures the numbers dialed on, or the originating number of a call to, a telephone line, without first obtaining a superior court order, unless you are the provider of the telecommunication service using it to operate or protect the service, to guard against fraudulent or unlawful use, or with the consent of the user of that service. |
|
| Pen register and trap and trace device installation or use |
Do not install or use a pen register or a trap and trace device on a telephone line without first obtaining a court order, unless you are a wire or electronic communication service provider acting to protect your own operations or property, to prevent fraudulent or unlawful use of your service, or you have obtained the user's consent. |
|
| Oregon Pen Register and Trap and Trace Device Statute |
Do not install or use a pen register or trap and trace device unless a court order or statute allows it; a device a provider or its customer uses for billing, or for cost accounting in the ordinary course of business, is not a pen register. |
|
| Consumer Protection Against Computer Spyware Act |
If you are not an authorized user of a computer (its owner, or a person its owner or lessee has authorized to use it), do not cause software to be copied onto the computer of an authorized user in Pennsylvania, or procure its copying, and use the software to do any of the acts listed below; sections 3 and 4 apply where you act with actual knowledge, with conscious avoidance of actual knowledge or willfully. Do not use deceptive means to collect personally identifiable information gathered by a keystroke-logging function that records all of a user's keystrokes and transfers them to another person, or that includes all or substantially all of the websites the user visits (other than the software provider's own) where the software was installed in a manner designed to conceal the installation from every authorized user, or by extracting from the hard drive, for a purpose wholly unrelated to any purpose of the software or service you described to the user, a credit or debit card or other financial account number, a password or PIN for a financial account, a Social Security number, or account balances or overdraft history in a form that personally identifies the user. +2 more |
|
| Pen Registers, Trap and Trace Devices and Telecommunication Identification Interception Devices, General Prohibition |
Do not install or use a pen register, a trap and trace device or a telecommunication identification interception device without first obtaining a court order, unless you are a provider of the wire or electronic communication service using it to operate, maintain or test the service, to protect the provider or its users from abuse, fraud or unlawful use, or with the consent of the user of the service. |
|
| Unlawful Use of Pen Register or Trap and Trace Device |
Do not knowingly install or use a pen register or trap and trace device to record or decode electronic or other impulses for the purpose of identifying telephone numbers dialed or otherwise transmitted on a telephone line. |
|
| PECR, Storage of and Access to Information on Terminal Equipment |
Do not store information on, or gain access to information already stored on, a subscriber's or user's terminal equipment (a phone, computer or other device, including through a browser or an app) unless they have been given clear and comprehensive information about the purpose of the storage or access and have given consent. |
|
| Virginia Pen Register and Trap and Trace Device Prohibition |
Do not install or use a pen register or a trap and trace device (a device or process that records dialing, routing, addressing or signaling information of a wire or electronic communication, excluding its contents) without first obtaining a court order under section 19.2-70.2; a device a provider or customer uses for billing, or for cost accounting in the ordinary course of business, is not a pen register. |
Commercial messages
15 laws, 13 places| Place | Law | What it asks, as read here |
|---|---|---|
| Spam Act 2003, Address-Harvesting Software and Harvested-Address Lists |
Do not supply, or offer to supply, address-harvesting software (software specifically designed or marketed for searching the internet for electronic addresses and collecting, compiling, capturing or otherwise harvesting them) or a harvested-address list, or a right to use either, to another person, where you or the customer is physically present in Australia or an entity carrying on business or activities in Australia at the time, if you have reason to suspect it will be used to send a commercial electronic message in contravention of section 16. Do not acquire address-harvesting software or a harvested-address list, or a right to use either, while you are physically present in Australia or an entity carrying on business or activities in Australia, if you intend to use it in connection with sending a commercial electronic message in contravention of section 16. +1 more |
|
| Spam Act 2003, Unsolicited Commercial Electronic Messages |
Obtain the relevant electronic account-holder's express consent, or consent reasonably inferred from their conduct and business or other relationships, before sending, or causing to be sent, a commercial electronic message (an email, SMS, instant message or similar account message, but not a voice call) that has an Australian link, unless it is a designated commercial electronic message exempt under Schedule 1. Treat a business or work electronic address as impliedly consenting only if it was conspicuously published, the publication appears to have the agreement of the person or organisation it belongs to, it carries no statement that unsolicited commercial messages are unwanted, and the message you send is relevant to the work, office, function or role the address was published for. +1 more |
|
| Unsolicited Text Message Advertisements |
If you are a person, business, candidate, or political committee in California, do not transmit a text message advertisement, one whose principal purpose is to promote the sale of goods or services or a political purpose, to a mobile telephone, pager, or two-way messaging device, unless an exception applies. |
|
| Canada's Anti-Spam Legislation |
Get the recipient's prior consent, express or implied, before sending a commercial electronic message (a term broad enough to reach email, SMS and other electronic messages) to an electronic address, unless an exemption applies. Treat consent as implied, without asking for it, only where you have an existing business relationship (a purchase, lease, barter, written contract, or gaming or investment opportunity within the last two years, or an inquiry or application within the last six months) or an existing non-business relationship (a donation, volunteer work, or membership with a registered charity, political party or candidate within the last two years), or where the recipient conspicuously published or gave you their address without saying they did not want unsolicited messages and the message is relevant to their business, role or duties. +1 more |
|
| Delaware Unrequested or Unauthorized Electronic Mail Statute |
Do not, without authorization, intentionally or recklessly distribute unsolicited bulk commercial electronic mail to a receiving address or account under the control of an authorized user of a computer system, unless the mail is sent between individuals, the recipient requested it, an organization sends it to its own members, or a preexisting business relationship exists. |
|
| ePrivacy Directive |
Obtain the recipient's prior consent before using an automated calling machine, a fax machine, or electronic mail (including a text message, which the Directive's own definition of electronic mail reaches) to send direct marketing to an individual. Where you collected a customer's electronic contact details in the course of selling them a product or service, you may market your own similar products or services to that customer without fresh consent, provided you offered a free, easy opt-out at the time of collection and offer it again, free of charge, in every message, unless the customer already refused. |
|
| Gesetz gegen den unlauteren Wettbewerb, Commercial Electronic Messages |
Obtain the addressee's prior express consent before advertising using an automatic calling machine, a fax machine, or electronic mail, unless the existing-customer exception below applies. You may market your own similar goods or services to an existing customer by electronic mail without fresh consent only if you obtained their electronic address in connection with a sale, they have not objected to that use, and you clearly told them, both when collecting the address and at every use, that they may object at any time at no cost beyond the basic transmission tariff. |
|
| Irish ePrivacy Regulations |
Obtain the recipient's prior consent before sending direct marketing to an individual by automated calling machine, fax, or electronic mail, a term that reaches SMS as well as email. If an SMS is sent for a purpose other than marketing but includes direct-marketing content, treat it the same as a marketing message and obtain the recipient's prior consent. +1 more |
|
| Nevada Unsolicited Commercial Electronic Mail Liability Act |
Before sending, or causing to be sent, email that includes an advertisement, either have a preexisting business or personal relationship with the recipient, obtain the recipient's express consent, or make the advertisement identifiable as promotional and clearly give your legal name, complete street address and email address, a notice of how to decline further advertising mail, and ADV or advertisement as the first word of the subject line. Do not disguise the source of an advertisement, use false or misleading subject-line information, give a false return address or a false address for declining mail, ignore a recipient's request to stop, or obtain a recipient's address by a method they did not authorize. |
|
| Fraudulent electronic mail messages |
Do not initiate an electronic mail message that you know or have reason to know misrepresents or omits information identifying its point of origin or transmission path, falsely claims to be sent by a legitimate online business, or links the recipient to a web page falsely represented as associated with a legitimate online business, to obtain identifying information the recipient believes is being given for a legitimate purpose. |
Show the other 5 laws
| Unsolicited Telecommunication Advertisement Act |
Do not use a covered mobile telephone messaging system to transmit an unsolicited commercial email message. |
|
| PECR, Electronic Mail for Direct Marketing Purposes |
Get the individual recipient's prior consent before sending, or instigating the sending of, unsolicited electronic mail, which reaches SMS and other messaging as well as email, for direct marketing purposes, unless the soft opt-in below applies. You do not need consent if you obtained the recipient's contact details in the course of a sale or sale negotiation with them, you market only your own similar products or services, and you gave the recipient a simple, free means of opting out at the time the details were collected and with every later message. +1 more |
|
| CAN-SPAM Act |
Do not harvest email addresses from a website or generate them by an automated dictionary attack, and do not falsify the domain name registration information used to send the mail. |
|
| Restrictions on Mobile Service Commercial Messages |
Do not send a commercial message to an address that resolves to a wireless carrier's messaging domain on the FCC's wireless domain names list, unless you have the addressee's express prior authorization naming your business and the address to be messaged. |
|
| Commercial Electronic Mail Act, Text Messages |
Do not initiate or assist in transmitting a commercial electronic text message to a telephone number assigned to a Washington resident for cellular telephone or pager service with text-messaging capability, unless an exception applies. You may send one only where the subscriber has clearly and affirmatively consented in advance to receive it, or, if you are the subscriber's own cellular or pager carrier, at no cost to the subscriber, unless the subscriber has said it does not want further commercial text messages from you. |
Cross border transfer
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Law, Cross-Border Transfer |
Give advance notice disclosing the overseas recipient's identity and contact details, and obtain the individual's separate consent, before transferring their personal information abroad. |
|
| Personal Data Protection Law, cross-border transfer |
An app transferring or exchanging the personal data of an individual in Jordan with another recipient must obtain the Data Subject's consent, confirm a legitimate interest on both sides, ensure the Data Subject has sufficient knowledge of the purpose, and must not use the data for marketing without a separate consent; Jordan's base Law does not impose an adequacy or localization gate on the transfer. |
|
| Data Protection Act, 2023, cross-border transfers of personal data |
Where you transfer without adequate protection on the data subject's consent, inform them of the risks of the transfer first, and stop if they withdraw consent. |
|
| Privacy Act 2025, transfers of personal information outside the Kingdom from a date not yet set |
Where you rely on the data subject's consent to transfer without adequate protection, inform them of the risks first and stop if they withdraw it. |
Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.