Law / Frameworks / NIST Privacy Framework / Govern-P

NIST Privacy Framework, Govern-PGV.PO-P5

Legal, regulatory, and contractual requirements regarding privacy are understood and managed.NIST Privacy Framework, version 1.0, January 2020, GV.PO-P5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

184
laws
110
places
1
with court rulings behind it
13
not yet in force
3
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Albania
  • Algeria
  • Andorra
  • Angola
  • Antigua and Barbuda
  • Argentina
  • Armenia
  • Australia
  • Bahamas
  • Bahrain
  • Barbados
  • Belarus
  • Belize
  • Benin
  • Bermuda
  • Bolivia
  • Bosnia and Herzegovina
  • Brazil
  • Burkina Faso
  • Cabo Verde
  • California
  • Cambodia
  • Cameroon
  • Canada
  • Cayman Islands
  • Central African Republic
  • Chad
  • Chile
  • China
  • Colombia
  • Comoros
  • Costa Rica
  • Côte d'Ivoire
  • Delaware
  • Democratic Republic of the Congo
  • Djibouti
  • Dominican Republic
  • Ecuador
  • Egypt
  • Eswatini
  • Ethiopia
  • European Union
  • Florida
  • Gabon
  • Gambia
  • Germany
  • Ghana
  • Grenada
  • Israel
  • Jamaica
  • Kenya
  • Kiribati
  • Kosovo
  • Lebanon
  • Lesotho
  • Liberia
  • Libya
  • Madagascar
  • Malawi
  • Mali
  • Malta
  • Marshall Islands
  • Maryland
  • Mauritania
  • Moldova
  • Monaco
  • Montana
  • Montenegro
  • Morocco
  • Nauru
  • Nevada
  • New Hampshire
  • New Zealand
  • Nicaragua
  • Niger
  • Nigeria
  • North Macedonia
  • Oklahoma
  • Oman
  • Oregon
  • Panama
  • Paraguay
  • Pennsylvania
  • Peru
  • Qatar
  • Republic of the Congo
  • Rwanda
  • Saint Kitts and Nevis
  • San Marino
  • Sao Tome and Principe
  • Senegal
  • Serbia
  • Somalia
  • South Africa
  • Suriname
  • Sweden
  • Syria
  • Tanzania
  • Texas
  • Togo
  • Tonga
  • Tunisia
  • Uganda
  • Ukraine
  • United States
  • Uruguay
  • Vanuatu
  • Washington
  • Zambia
  • Zimbabwe

Comprehensive regime

67 laws, 67 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024 On the Protection of Personal Data

Appoint a representative located in Albania and notify the Commissioner in writing of that representative's identity when you target people in Albania from outside the country, unless the processing is occasional, small scale, and unlikely to risk fundamental rights, or you are a public authority.

Algeria Loi n° 18-07 relative à la protection des personnes physiques dans le traitement des données à caractère personnel, modifiée et complétée par la loi n° 25-11

Where you are established outside Algeria but use automated or non-automated means located there, notify the ANPDP of the identity of your Algeria-based representative.

Submit every personal-data processing operation to a prior declaration to the ANPDP or its authorisation, before you begin.

Andorra LQPD, Llei 29/2021 del 28 d'octubre

Designate a representative established in Andorra if you are a controller or processor not domiciled there or not constituted under Andorran law but use processing means located in Andorran territory.

Angola Law on the Protection of Personal Data

Treat a recipient who processes communicated personal data for its own purposes as a controller in its own right, and one who processes it on your behalf and under your instructions as a subcontractor bound by a written contract, and obtain the APD's authorisation before interconnecting personal data held in different files unless a legal provision already permits it.

Notify the Agência de Protecção de Dados before processing personal data, or obtain its authorisation where notification is not enough, and give it the particulars the law requires about the processing.

Argentina Ley 25.326, Ley de Protección de los Datos Personales

Register any database intended to provide reports, public or private, with the National Registry before operating it, stating your identity, the file's purpose, its data sources, recipients, security measures, retention period, and how a data subject can exercise their rights, and do not hold data of a kind you did not declare.

Australia Privacy Act 1988 (Cth), Comprehensive Regime and Civil Penalties

Comply with the Australian Privacy Principles in Schedule 1 to the Privacy Act 1988 for any personal information about an individual, if the entity is an Australian Government agency or an organisation with an annual turnover over $3,000,000.

Comply with the Australian Privacy Principles for an act done, or a practice engaged in, outside Australia if the entity has an Australian link.

Barbados Data Protection Act, 2019

Register with the Data Protection Commissioner as a data controller or data processor before processing personal data.

Nominate a representative established in Barbados if you act as a data controller or data processor without being established there.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Declare each processing of personal data to the Autorité de Protection des Données Personnelles (APDP) before implementing it, or obtain the Autorité's prior authorization where the processing falls into one of its listed higher risk categories.

Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel

Complete the applicable prior formality with the Commission de l'informatique et des libertés (CIL) before processing personal data, a normal or simplified declaration, a request for its opinion, or its authorization depending on the category of processing.

Obtain a CIL authorization before interconnecting personal data files or processing a national identification number, and limit any interconnection to a legitimate legal or statutory objective without discriminating against or reducing the rights of the people concerned.

+1 more
Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data

Obtain the CNPD's authorisation under article 23, or point to a legal provision, before combining personal data from different filing systems, and ensure any combination serves a legitimate purpose, avoids discrimination, and carries adequate security measures.

Notify the CNPD before carrying out an automated personal data processing operation, and obtain the CNPD's prior authorisation for processing of sensitive data, credit and solvency data, combined data across filing systems, or data reused for a new purpose.

Show the other 57 laws
Cambodia Draft Law on Personal Data Protection, final draft proposed

If enacted as drafted, a data controller and processor would each have to appoint a personal data protection officer and notify the Ministry of Post and Telecommunications of that appointment within 30 working days, maintain records of processing activities, and, if located outside Cambodia, appoint a local representative.

Cameroon Loi n°2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun from a date not yet set

Obtain the data protection authority's prior authorization before processing personal data of a person established, resident, or in transit in Cameroon.

Central African Republic Loi n° 24.001 portant protection des données à caractère personnel

Get the agency's prior authorization before interconnecting personal data files held for different purposes or by different controllers, stating in the request the nature of the data, the interconnection's purpose, and its duration.

Chile Ley 21.719, Regula la Protección y el Tratamiento de los Datos Personales from , in 2 months

Prepare to register and report to the new Agencia de Protección de Datos Personales once the law commences; the current regulator structure under Ley 19.628 does not yet include a dedicated data-protection authority.

Colombia Ley 1581 de 2012, General Personal Data Protection

Register your databases with the Superintendencia de Industria y Comercio's National Registry of Databases and submit data treatment policies that never fall below this law's duties.

Comoros Law on the Protection of Personal Data

Declare personal data processing to the Commission before implementing it, or enter it in a register kept by a designated person, unless it is exempt as general accounting, payroll, supplier management, or a non profit association's membership processing.

Obtain the Commission's prior authorization before processing a national identification number or a national census, processing concerning state security, defense or public safety or the investigation and prosecution of offenses, interconnecting files serving different purposes, or processing that could exclude a person from a right, a benefit or a contract.

+2 more
Costa Rica Protección de la Persona frente al Tratamiento de sus Datos Personales

Register any database administered for distribution, dissemination, or commercialization purposes with the Prodhab.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data

Declare the processing to ARTCI in advance, or designate an internal correspondent for the protection of personal data in its place, except before a cross-border transfer.

Obtain ARTCI's prior authorization before processing on a national identification number or a personal-data set of public-interest, historical or scientific research value.

Democratic Republic of the Congo Digital Code, Title III: Personal Data Protection

File a prior declaration with the Data Protection Authority before processing personal data, or obtain its prior authorization before processing genetic, medical, biometric, offense or conviction, national-identification, or cross-border-transfer data.

Djibouti Digital Code, Book I: Personal Data Protection and CNDP

File a prior declaration with, or obtain the prior authorization of, the Commission Nationale de Protection des Données à Caractère Personnel before processing personal data, depending on the processing's risk category.

Dominican Republic Ley No. 172-13 sobre Protección Integral de los Datos Personales

Register as a Sociedad de Información Crediticia with the Superintendencia de Bancos, after securing the Junta Monetaria's authorization, before operating as a credit reporting bureau.

Ecuador LOPDP, comprehensive personal-data protection regime

Register with the national register of personal data protection as article 51 requires.

Eswatini Data Protection Act, 2022 (Act No. 5 of 2022)

Notify the Eswatini Communications Commission of your processing of personal information before you process it, and again whenever the particulars you notified change.

Ethiopia Personal Data Protection Proclamation

Register with the Ethiopian Communications Authority before processing personal data, and appoint a data protection officer where the Proclamation requires one.

Obtain the Authority's prior authorization where you cannot provide appropriate safeguards for a transfer to a third-party jurisdiction, and consult the Authority before processing where an impact assessment indicates the operations are likely to present a high risk.

Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Declare an automated personal-data processing activity to the APDPVP before carrying it out and wait for the Authority's receipt before starting, unless a simplified or exempt category applies; processing touching a more sensitive category instead needs the APDPVP's prior authorization or a ministerial or Council-of-Ministers decree.

Before deploying an artificial-intelligence system, a facial-recognition or other biometric-identification system, a drone or other connected object, an electronic-signature or digital-identity service, or a national or sectoral identifier system that processes personal data, file the declaration or notice the applicable norme or decree requires with the APDPVP.

Ghana Data Protection Act

Have a lawful basis for processing personal data, and register with the Data Protection Commission before processing begins.

When registering as a data controller, disclose the countries to which personal data may be transferred.

Israel Protection of Privacy Law, comprehensive regime and database registration

An app that operates a database of the personal data of individuals in Israel above the small-collection thresholds must register with, or separately notify, the Privacy Protection Authority under Art. 8A, and must name a Data Protection Officer where the Act requires one.

Jamaica Data Protection Act, 2020, registration, lawful basis and standards for processing

Register with the Office of the Information Commissioner before processing personal data, and keep your registration particulars in the register the Commissioner maintains.

Appoint a representative established in Jamaica if you are not established there but process the personal data of data subjects in Jamaica to offer them goods or services or to monitor their behaviour.

Kenya Data Protection Act, 2019

Register with the Office of the Data Protection Commissioner if your volume or category of processing meets the prescribed threshold.

Kosovo Law No. 06/L-082 on Protection of Personal Data

Appoint a registered representative in Kosovo if you are a controller or processor not established there but use automatic or other equipment in Kosovo to process personal data, unless that equipment is used only for transit through Kosovo.

Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than two hundred and fifty people and none of the high-risk, non-occasional or special-category exceptions apply, and cooperate with the Agency for Information and Privacy on request.

+1 more
Lebanon Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection)

File a permit with the Ministry of Economy and Trade, issued against a receipt, before collecting or processing the personal data of a person in Lebanon, unless one of the exemptions in Article 94 covers the processing.

State in that permit the objectives of the processing, the personal data and its source, the categories of persons concerned, the third parties who may view the data, the retention period, your identity and address and those of your representative if you live outside Lebanon, the agency carrying out the processing, who exercises the right of access and how, any subcontractor, and the measures you take to keep the data intact.

+2 more
Lesotho Data Protection Act, 2011 (Act No. 5 of 2012)

Notify the Data Protection Commission of your processing of personal information before you process it, and again whenever the particulars you notified change.

Liberia Data Protection Act of Liberia from a date not yet set

Handle personal information collected, processed, transmitted, stored, or used in Liberia in line with Liberia's Data Protection Act, whose specific consent, notice, and data-subject-rights provisions are not described here.

Madagascar Law No. 2014-038, protection of personal data

Declare a processing operation to the CMIL before implementing it, or obtain its prior authorization first where the processing presents a particular risk to rights and freedoms or to privacy.

Malawi Data Protection Act, 2024 from a date not yet set

Comply with the Data Protection Act, 2024's rules for collecting, processing, storing, and sharing personal data, whether the personal data belongs to a private individual or is held by a public organisation.

Mali Loi n° 2013-015, protection des données à caractère personnel

Declare to the Autorité de Protection des Données à Caractère Personnel, before carrying it out, any processing operation you intend to carry out for a given purpose.

Mauritania Loi n° 2017-020, protection des données à caractère personnel

Complete the Personal Data Protection Authority's prior formalities before processing personal data; failing to do so, even negligently, is a criminal offence.

Declare your processing to the Authority before you start it, unless article 32 exempts it.

+1 more
Moldova Law No. 195/2024 on Personal Data Protection

Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the National Centre for Personal Data Protection beforehand where that risk remains.

Monaco Loi sur la Protection des Données Personnelles

Carry out a data protection impact assessment before processing likely to create a high risk to a person's rights and freedoms, such as large scale profiling with legal effects, large scale sensitive data processing, large scale public area surveillance, or large scale use of a digital identifier, and consult the Authority first where the assessment still shows a high risk you cannot mitigate.

Get the Minister of State's prior authorisation before installing a video surveillance system in a place open to the public or filming a public way, and do not keep recorded images for more than 30 days.

Montenegro Law on Personal Data Protection from a date not yet set

Keep records of every personal data filing system you establish, covering the matters Article 26 lists, and obtain the Agency for Personal Data Protection and Free Access to Information's prior consent before establishing or materially altering one, under Articles 27 and 28.

Morocco Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

File a prior declaration with the CNDP before implementing an automated processing operation, or a set of related automated operations, unless the processing instead requires the CNDP's prior authorization.

If you are established outside Morocco but use processing means located there, notify the CNDP of the identity of a Morocco based representative who takes on your rights and obligations under the law.

+1 more
Nauru Communications and Broadcasting Act 2018, confidentiality of subscriber information and communications

If the Chief Regulator directs you to under section 49(4), monitor communications to a subscriber's connections to trace a harassing, offensive, or illegal call, to the extent your current technology allows.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales

Register with the data file register the Direccion de Proteccion de Datos Personales keeps before operating a data file, and wait for its registration decision within thirty days.

Niger Loi n° 2022-59, protection des données à caractère personnel

Collect, record, process, store and transmit personal data lawfully, fairly and without fraud.

Complete a prior declaration, authorisation request or advisory request with the HAPDP before implementing a processing operation, and obtain its prior authorisation for genetic, medical, biometric, interconnected, unique-identifier or sensitive-category processing.

Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Register with the Commission as a data controller or data processor of major importance where the Commission so determines, conduct a compliance audit within fifteen months of commencing business and annually thereafter, and file Compliance Audit Returns by 31 March each year in the Ultra-High and Extra-High Level categories.

Tell the Commission of any significant change to the information in your most recent registration submission within sixty days of the change.

North Macedonia Law on Personal Data Protection (LPDP)

Get the Agency's prior approval before any systematic and extensive processing of a citizen's national identification number, and otherwise process it only with the data subject's prior consent or another case a law states.

Paraguay Ley N° 7593/2025, de Protección de Datos Personales en la República del Paraguay from , in 14 months

Carry out an impact assessment before implementing processing that warrants one, and consult the supervisory authority beforehand where article 15 requires it.

Peru Ley 29733, Ley de Protección de Datos Personales

Register your personal-data bank with the Registro Nacional de Protección de Datos Personales before creating it, or, for a bank that predates the Law, declare it to the Authority within the deadline the regulation sets.

Republic of the Congo Law No. 29-2019 on the Protection of Personal Data

File a prior declaration of processing with the national commission, unless the processing is exempt, requires the commission's prior authorization under article 37, or requires a presidential decree issued after the commission's opinion under article 40.

Rwanda Law relating to the Protection of Personal Data and Privacy

Register with the supervisory authority as a data controller or data processor before processing personal data, and designate a data protection officer where article 40 requires one.

San Marino San Marino Law No. 171 on the Protection of Natural Persons

Implement technical and organisational measures giving a level of security appropriate to the risk, and cooperate with the Data Protection Authority in the performance of its tasks.

Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the Data Protection Authority beforehand where the assessment shows that risk remains.

Sao Tome and Principe Lei n.º 03/2016, Protecção de Dados Pessoais

Notify the National Agency for the Protection of Personal Data (NAPPD) in writing at least eight days before starting a wholly or partly automated processing operation.

Obtain NAPPD's prior authorization before processing credit or solvency data, interconnecting personal-data files, or using collected data for a purpose other than the one it was collected for.

+2 more
Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act)

Declare your processing to the CDP before you start it, using its published form, and do not implement the processing until you receive the CDP's certificate of receipt.

Get the CDP's authorization before combining personal data files across purposes or processing a national identification number or other general-purpose identifier.

Serbia Law on Personal Data Protection

Appoint a written representative in Serbia when established outside Serbia and processing personal data of a person there, unless a listed exemption applies.

Carry out a data protection impact assessment before processing likely to create high risk to a person's rights and freedoms, and consult the Commissioner first where the assessment shows the risk cannot be brought down.

Somalia Data Protection Act No. 005 of 2023

As a data controller of major importance, carry out a data protection impact assessment before processing likely to result in a high risk to a data subject, and submit the assessment report to the Authority before you start.

As a data controller of major importance, register with the Authority within six months of qualifying, and designate a data protection officer.

South Africa Protection of Personal Information Act 4 of 2013 (POPIA)

Obtain the Information Regulator's prior authorisation before linking data subjects' unique identifiers across responsible parties, processing criminal-behaviour or credit-reporting information, or transferring special personal information or a child's information to a country without adequate protection.

Suriname Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens) proposed

Keep a written or electronic register of your processing activities, covering the categories of data, recipients, retention periods, and security measures, and notify it to the Commissioner for Personal Data Protection, updating the notification whenever needed and at least once a year.

Sweden Kamerabevakningslagen (Camera Surveillance Act)

Run a documented impact assessment weighing public interest against individual privacy, and register the surveillance, before operating a camera or optical-electronic monitoring system in Sweden, whether or not it performs facial recognition.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data

Obtain a license or permit from the Personal Data Protection Authority before collecting, storing, transferring or processing personal data, and appoint a local representative if you are established outside Syria.

Tanzania Personal Data Protection Act, 2022

Register with the Personal Data Protection Commission before collecting or processing personal data.

Togo Loi n° 2019-014, protection des données à caractère personnel

Declare personal data processing to the Instance de Protection des Données à Caractère Personnel before implementing it, unless the processing is exempt from formalities, requires prior authorization, or requires a reasoned government opinion.

Obtain the Instance's prior authorization before interconnecting files that serve different purposes, processing a national identification number or other general purpose identifier, or processing personal data for a historical, statistical or scientific public interest purpose.

Tunisia Organic Act on the Protection of Personal Data

File a prior declaration with the National Authority for the Protection of Personal Data (INPDP) before processing personal data, or obtain its prior authorization where the Act requires one.

Tell the INPDP at least three months before permanently ceasing your processing activity, or within three months of a controller's death, bankruptcy or dissolution, so it can authorize the data's destruction.

+1 more
Uganda Data Protection and Privacy Act, 2019, comprehensive personal-data regime

Register with the National Information Technology Authority as a data controller or other prescribed person before collecting or processing personal data.

Ukraine Law of Ukraine On the Protection of Personal Data

Notify the Ombudsperson before beginning to process biometric data, genetic data, health data, or another listed risky category of a person in Ukraine, under Article 7's notification-based mechanism; this law does not define biometric data anywhere, including in its Article 2 definitions.

Uruguay Ley N° 18.331, Personal Data Protection and Habeas Data Law, as amended

Register any database of personal data you create, modify, or eliminate with the Unidad Reguladora y de Control de Datos Personales before operating it, and hold only the categories of data you declared in that registration.

If established outside Uruguay while offering goods or services to, or analyzing the behavior of, people in Uruguay, or using means located there, designate a locally domiciled representative before the Unidad Reguladora y de Control de Datos Personales.

Zambia Data Protection Act, 2021, personal data processing framework

Register with the Data Protection Commissioner as a data controller or data processor before controlling or processing personal data.

Tell the Data Protection Commissioner of any third-party agreement that lets a third party trade on a data subject's profile.

Zimbabwe Cyber and Data Protection Act [Chapter 12:07]

Notify the Authority before any wholly or partly automated processing operation, and notify it again of any modification to the information you gave.

State in that notification the date and the instrument permitting the processing, who you are, what the processing is called and what it is for, the categories of data and of data subjects, the safeguards on disclosure to third parties, how data subjects are informed and can exercise access, any linked processing, the retention period, an assessment of whether your security measures are adequate, any data processor you use, and the transfers you plan.

Enforcement supervision

64 laws, 64 places
PlaceLawWhat it asks, as read here
Albania Law No. 124/2024, Commissioner, remedies, liability and penalties

Comply with a Commissioner order such as a warning, a notice, a processing restriction, a rectification or erasure order, or a suspension of a data transfer, and expect an administrative fine reaching 2,000,000,000 Albanian Lek or 4% of worldwide annual turnover, whichever is higher, for the most serious violations, or 1,000,000,000 Lek or 2% for the minors' online consent rule, the non-identification rule, and most of the controller and processor obligations chapter other than Article 22 itself.

Algeria Loi n° 18-07 relative à la protection des personnes physiques, contrôle, sanctions et voies de recours

Answer the ANPDP's own inspections and audits, and expect the tiered criminal penalties this law sets, from a fine alone up to five years' imprisonment, for the specific duty you breach.

Andorra LQPD, the Andorran Data Protection Agency, its powers, infractions and sanctions

Cooperate with an Agency investigation, including giving inspectors access to your premises, equipment, processing means and any information they request.

Comply with a corrective order the Agency issues, which can include a warning, a reprimand, an order to fulfil a data subject's rights request, an order to bring processing into compliance, a temporary or definitive limitation or ban on processing, or an order suspending data flows to a third country.

Angola Law on the Protection of Personal Data, enforcement and supervision

Register a code of conduct with the APD before relying on it, and expect the APD to reject a code that conflicts with this law or other applicable legislation.

Interrupt, cease or block processing once the APD has notified you to do so, and cooperate with an APD request, on pain of up to three years' imprisonment or a corresponding fine for qualified disobedience.

Antigua and Barbuda Data Protection Act, 2013, information commissioner and enforcement

Comply with a requirement the Information Commissioner specifies in an enforcement notice or an information notice, and expect an appeal against that requirement, or against a decision of the Information Commissioner, to lie to the Eastern Caribbean Supreme Court.

Argentina Ley 25.326, enforcement, sanctions, and the habeas data action

Give the control body the antecedents, documents, programs, or other elements about your personal-data processing that it requests, and let it verify your compliance with the Act, including through a judicially authorized inspection.

Register a private-sector code of conduct for personal-data processing practices with the control body before relying on it as your compliance standard.

Bahamas Data Protection Act 2003, Commissioner, enforcement and penalties

Comply with an enforcement notice the Data Protection Commissioner serves requiring rectification, erasure or another specified step.

Barbados Data Protection Act, 2019, the Commissioner, enforcement and penalties

Comply with an enforcement notice the Commissioner serves within the time it specifies, including any requirement to stop processing personal data or a description of personal data, because failing to comply with a notice is itself an offence.

Answer an information notice or a special information notice from the Commissioner, and do not obstruct the execution of a warrant issued under the Act.

Belarus Law of the Republic of Belarus On Personal Data Protection, authorized agency and liability

Comply with the National Center's requirement to rectify, restrict or erase false or illegally obtained personal data, or to eliminate another violation of this Law, under Article 16 and Article 18, paragraph 3.

Belize Data Protection Act 2021, Commissioner, Tribunal, and enforcement from a date not yet set

Comply with an Enforcement Notice, Information Notice, or Special Information Notice the Data Protection Commissioner issues, or answer to the Data Protection Tribunal on appeal.

Show the other 54 laws
Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, Autorité de Protection des Données Personnelles, sanctions et infractions pénales

Comply with a formal notice the Autorité issues within the period it sets, which may not exceed eight days, before it moves to a sanction.

Do not obstruct the Autorité's investigations, and furnish it, its designated agents, or its members the information, documents, and premises access they request.

+1 more
Bermuda Personal Information Protection Act 2016, Commissioner, enforcement and offences

Comply with an order or notice served by the Privacy Commissioner under this Act.

Do not contravene the sensitive personal information restriction, and do not dispose of, alter, falsify, conceal or destroy evidence during a Commissioner investigation or inquiry.

Bosnia and Herzegovina Law on the Protection of Personal Data of Bosnia and Herzegovina, the Agency, enforcement and penalties

Comply with an Agency order under Article 103, including a warning, a compliance order, a temporary or permanent restriction on processing, or a suspension of a transfer abroad, since defying one carries its own fine.

Brazil LGPD, civil liability, administrative sanctions and the ANPD

Comply with an ANPD warning's corrective-measures deadline before facing escalation to a fine, publicity of the infraction, blocking or deletion of the data involved, or suspension of the processing activity.

Burkina Faso Personal Data Protection Law, supervisory authority and sanctions

Cooperate with a CIL verification or control mission on site, including any expert it brings, and pay the mission's costs yourself if you were the one who requested the control.

Take all useful measures to facilitate the CIL's mission, and do not obstruct its action for any reason.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision

Submit a code of conduct to the CNPD before relying on it, and expect the CNPD to declare whether it complies with the data protection laws and regulations in force.

Interrupt, cease or block processing once notified to do so, cooperate with a CNPD request, and destroy personal data once its retention period under article 6 has elapsed, on pain of the penalty for qualified non-compliance.

Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, article 74 (atteinte à la vie privée et traitement illicite des données à caractère personnel)

Do not process personal data without complying with the prior declaration or authorization formalities the law requires before implementing the processing.

Cayman Islands Data Protection Act 2021 Revision, Ombudsman enforcement, monetary penalties and offences

Cooperate with a warrant executed under section 52 to investigate a suspected contravention of the data protection principles or an offence under the Act.

Chad Loi n°007/PR/2015, sanctions administratives et pénales et recours

Comply with an ANSICE warning or formal notice to cease a failure within the period ANSICE sets, on pain of a regulatory penalty and, for the underlying violation, criminal prosecution.

Meet the collection, purpose-limitation, sensitive-category, information, access-response, notification, declaration, and cross-border transfer conditions the law sets, each of which carries its own criminal exposure on breach.

+1 more
China Personal Information Protection Law, Supervision and Legal Liability

Comply with lawful CAC and sectoral-regulator investigation, including document production and on-site inspection.

Comoros Law on the Protection of Personal Data, the Commission and sanctions

Comply with a warning or formal notice the Commission issues within the period it sets, no more than eight days, or face a pecuniary sanction, an injunction to stop the processing, withdrawal of an authorization, or a data lock, after a contradictory procedure.

Do not obstruct the Commission's action and take useful measures to facilitate its mission, including letting its members and agents access the premises where processing is carried out.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data, enforcement and the Protection Body

Respond to ARTCI's declarations, authorization requests, claims, complaints and audits, and comply with a warning or formal notice it issues within the time it sets.

Do not invoke professional secrecy against the Protection Body, whether you are a cryptologic service provider or the person responsible for the processing.

+2 more
Democratic Republic of the Congo Digital Code, Data Protection Authority and sanctions

Do not obstruct the Data Protection Authority's on-site inspection, and expect a warning or a formal notice giving you no more than eight days to end a breach before a sanction follows.

Djibouti Digital Code, Book I: the Commission, administrative sanctions and criminal offences

Comply with a formal notice the Commission addresses to you, or expect an injunction, a withdrawal of authorization, the locking of the data concerned, or an administrative sanction of up to 70,000,000 Djiboutian francs or 5% of your worldwide turnover, whichever is higher, plus a daily penalty payment for continued non-compliance.

Egypt Egypt Personal Data Protection Law, the Center, judicial control and penalties

Expect the Personal Data Protection Center to decide a complaint against you within thirty working days of its submission, and carry out its decision within seven working days of being told of it, telling the Center once you have.

Eswatini Data Protection Act, 2022, enforcement and offences

Comply with an enforcement notice the Commission serves within the period it specifies, whether to take steps or to stop processing personal information, and know that you may apply to the Commission or a court to cancel, vary, or appeal it.

Cooperate with a Commission investigation, including giving evidence on summons and not obstructing entry and search of premises it reasonably suspects are connected with regulated activities.

Ethiopia Personal Data Protection Proclamation, enforcement, sanctions and offences

Comply with an enforcement order the Authority serves within the period it specifies, which is never less than twenty-one days, then tell the data subject concerned and, where compliance materially modifies the data, anyone it was disclosed to in the twelve months before the order was served.

Furnish the Authority with information it requests, in a form that can be taken away and is intelligible and retrievable, and cooperate with it in discharging its powers and functions.

Gabon Law No. 025/2023, recourse, oversight and sanctions

Produce any document the APDPVP's members or agents request for their mission, and let them access your programs and data for control purposes.

Gambia Personal Data Protection and Privacy Act, 2025, the Information Commission, offences and penalties from a date not yet set

Do not obstruct an investigation by the Information Commission, which carries up to seven years of imprisonment.

Ghana Data Protection Act, enforcement, offences and penalties

Comply with an enforcement notice the Commission serves within the time it states, and rectify, block, erase, or destroy other data containing an opinion based on data the Commission finds was processed in contravention of the Act.

Comply with an information notice or enforcement notice the Commission issues after assessing a data subject's complaint about your processing.

Grenada Data Protection Act, No. 1 of 2023, Information Commission, enforcement and offences from a date not yet set

Cooperate with an Information Commission investigation, complaint, information notice or warrant, and furnish the access, documentation and security information it requests.

Comply with an enforcement notice within the time it specifies, and where compliance materially modifies personal data, notify the data subject and anyone the data was disclosed to in the twelve months before the notice.

+1 more
Jamaica Data Protection Act, 2020, the Information Commissioner, penalties and compensation

Comply with an enforcement notice, an assessment notice or an information notice from the Information Commissioner, and do not make a statement in purported compliance with one that you know, or recklessly disregard, to be false in a material respect.

Kiribati Data Protection Act 2025, enforcement, offences and civil remedies from a date not yet set

On commencement, comply with a notice the Office issues after investigation requiring you, within a specified period, to stop or refrain from the violating act, compel a downstream processor to do the same, remedy the violation including compensating an affected data subject, or pay an administrative penalty of up to $100,000, proportionate to the violation's gravity, your efforts to comply, any profit made, and the harm caused.

On commencement, comply with any notice issued under sections 27 or 28 that is not under a duly made and ongoing appeal, or risk an offence carrying a fine of up to $100,000 and imprisonment of up to ten years, or both; that liability does not release or reduce any liability arising from the underlying notice.

Kosovo Law No. 06/L-082 on Protection of Personal Data, remedies, the Agency, inspections and penalties

Cooperate with an Agency inspection, including giving inspection officers access to documentation, computers, equipment and premises relevant to personal data processing.

Comply with a corrective order an inspection officer issues, which can require correcting irregularities, destroying, blocking or anonymising personal data, temporarily halting unlawful processing, or fulfilling a data subject's rights request.

Lesotho Data Protection Act, 2011, enforcement and offences

Comply with an enforcement notice the Commission serves within the period it specifies, whether to take steps or to stop processing personal information, and know that you may apply to the Commission or a court to cancel, vary, or appeal it.

Cooperate with a Commission investigation, including giving evidence on summons and not obstructing execution of a warrant issued to enter and search premises.

Libya Law No. 6 of 2022, supervisory authority, licensing and penalties

Obtain a license from the National Authority for Information Security and Safety before providing authentication services that involve collecting personal data.

Madagascar Law No. 2014-038, CMIL, sanctions and offences

Comply with any warning, injunction to stop processing, withdrawal of authorization, or monetary sanction the CMIL orders after an adversarial procedure, and with any urgent interruption or data-locking order it issues for up to three months.

Give CMIL inspectors on a control mission access to your premises between six in the morning and seven at night, unrestricted access to your files, processing, and equipment, and copies of any information they request.

Mali Loi n° 2013-015, the Autorité, supervision, and sanctions

Do not obstruct the Autorité de Protection des Données à Caractère Personnel's action, and take every measure useful to facilitate its work, including its information and on-site inspection missions.

Comply with an administrative sanction decision; the Autorité may use any technical means at its disposal to enforce it, though it may agree to settle a pecuniary sanction with you at your request, within the scales the law fixes.

Marshall Islands Personal Data Protection Act 2025, competent authority, remedies, and complaints

Provide the competent authority, the Economic Policy, Planning and Statistics Office, with information it requests as needed for it to carry out its duties under this Chapter.

Comply with any regulation the competent authority makes, with Cabinet approval, to implement this Chapter.

Mauritania Loi n° 2017-020, Autorité de Protection des Données et sanctions

Cooperate with the Authority's on-site inspections, and take all measures needed to facilitate its work rather than opposing its action.

Comply with an Authority warning or formal notice within the period it sets, or face suspension or definitive withdrawal of your processing authorization and a pecuniary fine of up to ten million ouguiya for a first breach, or up to fifty million ouguiya or five percent of turnover for a repeat breach within five years.

Moldova Moldova Law No. 195/2024, the Centre, complaints, compensation and sanctions

Answer the Centre's examination procedure once it is opened against you, and expect the sanctions the law provides at the end of it.

Monaco Loi sur la Protection des Données Personnelles, autorite de controle et sanctions

Comply with the Authority's formal notice to bring processing into conformity or to satisfy a data subject's rights request, within the period it sets, since noncompliance can draw a daily penalty of up to 10,000 euros that does not apply to the State or the Commune.

Cooperate with the Authority's checks and investigations, giving its members, agents, and sworn investigators the information, documents, and premises access they need, since only national security secrecy, attorney client privilege, journalistic source secrecy, and individual medical secrecy channelled through a designated physician can be raised against them.

Montenegro Law on Personal Data Protection, agency, supervision and penal provisions from a date not yet set

Give the Agency's controllers access to your filing systems, files and electronic processing means on request, regardless of the level of data secrecy, under Articles 65 to 67, and comply with an Agency order to eliminate irregularities, stop unlawful processing, erase unlawfully collected data, or stop an unlawful transfer or entrusting of personal data, under Article 71.

Morocco Law No. 09-08, the CNDP and sanctions

Cooperate with the CNDP's investigations, give its commissioned agents access to your processing facilities, data, and documents, and comply with any order it issues to correct, block, erase, or destroy data, or to suspend or halt a processing operation.

Comply at once with a CNDP decision withdrawing your declaration receipt or authorization because your processing threatens public security or order or offends morality.

New Zealand Privacy Act 2020, Compliance Notices and Offences

Comply with a compliance notice issued by the Commissioner to remedy a breach of the Act, an interference with privacy, or a breach of a code of practice, or face enforcement proceedings before the Human Rights Review Tribunal.

Do not obstruct, hinder, or resist the Commissioner, make a false or misleading statement, falsely claim authority under the Act, impersonate an individual to obtain or alter their personal information, or destroy a document to defeat a request; each is an offence carrying a fine of up to $10,000.

Nicaragua Ley No. 787, Ley de Protección de Datos Personales, supervision, sanctions, and complaints

Cooperate with an accredited inspector's visit by allowing access to your data files, supplying the requested information and documents, including your registration and security measures, and allowing your equipment to be reviewed.

Niger Loi n° 2022-59, contrôle, sanctions et recours

Comply with a HAPDP warning or formal notice to end a violation within the deadline it sets, or risk provisional or definitive withdrawal of your processing authorisation and a pecuniary sanction.

Give a control agent the HAPDP assigns access to the premises and installations where you carry out processing, other than a private home, to verify your compliance.

Nigeria Nigeria Data Protection Act, 2023, complaints, enforcement and redress

Attend a Pre-Action Conference as often as the Commission calls one in respect of a complaint or an investigation under section 46(3) of the Act.

North Macedonia Law on Personal Data Protection (LPDP), the Agency, supervision and misdemeanour provisions

Cooperate with the Personal Data Protection Agency's supervisors during a regular, irregular or control supervision, including granting access to premises, documents and equipment relevant to personal data processing.

Panama Ley 81 de 2019, enforcement and sanctions

Cooperate with ANTAI's information requests and inspections and respond to its formal notices and observations; failing to do so is itself a serious infraction.

Peru Ley 29733, enforcement, supervisory authority and sanctions

Register your personal-data bank in the Registro Nacional de Protección de Datos Personales, and expect any cross-border data-flow communication, sanction, or precautionary or corrective measure to be recorded there too.

Comply with an accessory obligation the sanctioning procedure imposes within its deadline, or expect a coercive fine of up to 10 UIT on top of the underlying sanction.

Rwanda Law relating to the Protection of Personal Data and Privacy, supervisory authority, penalties and offences

Comply with the supervisory authority's oversight, including its inspections, its register of data controllers and processors, and any regulation it issues to implement this Law.

Saint Kitts and Nevis Data Protection Act, 2018, Information Commissioner, enforcement and offences from a date not yet set

Furnish the Information Commissioner with access to personal data, documentation of its processing, or information about its security, in writing within the time an information notice specifies.

Comply with an enforcement notice the Information Commissioner serves within the time it states, and notify the data subject and anyone the data was disclosed to in the twelve months before the notice, within thirty days of complying, if compliance materially modifies the data.

+1 more
San Marino San Marino Law No. 171, the Data Protection Authority, remedies and fines

Answer the Authority's requests for information and documents, and expect verifications, including the special verifications article 63 provides for.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, Commission des Données Personnelles et sanctions

Cooperate with the CDP's on-site inspections and give its members or agents any document they need for their mission.

Comply with a CDP warning or formal notice within the period it sets, or face suspension or definitive withdrawal of your processing authorization and a pecuniary fine of one million to one hundred million CFA francs.

Somalia Data Protection Act, 2023, complaints, orders of the Authority and civil remedies

Comply with an order of the Authority, or apply to the Supreme Court for judicial review within thirty days: failing to comply is an offence carrying the same fine and up to two years' imprisonment.

South Africa Protection of Personal Information Act, the Information Regulator, enforcement and penalties

Comply with an enforcement notice the Regulator serves requiring you to take, or stop taking, specified steps, or appeal it to the High Court within 30 days.

Suriname Draft Law on the Protection of Privacy and Personal Data, Commissioner, remedies and fines proposed

Cooperate with the Commissioner for Personal Data Protection, an independent authority the bill would establish, including by giving access to the records, information, and premises the Commissioner needs to investigate a complaint.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, Authority, complaints and penalties

Comply with a stop order the Director General serves within the period it specifies, or expect the Board to warn of, suspend, or revoke your license, permit or accreditation, publish the violation at your expense, or place you under the Authority's technical supervision.

Togo Loi n° 2019-014, cadre institutionnel et dispositions pénales

Comply with a warning or formal notice the Instance issues within the period it sets, or face a provisional or, ultimately, definitive withdrawal of your authorization, an administrative fine of up to XOF 100,000,000, interruption of the processing, data locking, or a daily penalty of up to XOF 5,000,000, after a hearing.

Do not obstruct the Instance's action by opposing its members' or agents' missions, refusing to communicate the information or documents they request, or supplying information that does not match your records.

Tonga Privacy Act 2025, penalties, enforcement and third party actions from a date not yet set

Comply with an enforcement notice the Privacy Commission serves on you, and with an information notice in an investigation.

Tunisia Organic Act on the Protection of Personal Data, enforcement and sanctions

Cooperate with the INPDP's investigations, let it take statements and inspect the premises where processing took place other than a private home, and do not obstruct its work or give it inaccurate information in bad faith.

Vanuatu Data Protection and Privacy Act 2024, enforcement powers and offences

Provide a document or information the Deputy Commissioner requests in writing to determine whether the Act has been contravened, within 14 days of receiving the request.

Do not destroy, conceal, alter or falsify personal data or other material to prevent its disclosure to a data subject or to the Deputy Commissioner.

Zimbabwe Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Obtain a data controller licence from the Data Protection Authority before processing personal information, if you decide the means, purpose or outcome of processing, decide what data to collect or from whom, or obtain commercial gain from the processing.

Appoint a certified data protection officer and notify the Authority of the appointment in writing.

+2 more

Sensitive categories

25 laws, 25 places
PlaceLawWhat it asks, as read here
Angola Law on the Protection of Personal Data, sensitive data categories

Notify the Agência de Protecção de Dados of sensitive-data processing carried out under a legal provision, and carry it out with guarantees of non-discrimination and special security measures.

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, données sensibles et mineurs

Obtain the Autorité's prior authorization before processing personal data covered by Article 394, personal data processed for journalism, research, artistic, or literary purposes under Article 397, a national identification number, or biometric data.

Burkina Faso Personal Data Protection Law, sensitive personal data categories

Obtain a Commission de l'informatique et des libertés (CIL) authorization before processing genetic or biometric data in the private sector, including for health research, and before processing personal data about offenses, convictions or safety measures in the private sector.

Cabo Verde Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories

Process health and sex life data, including genetic data, only through a health professional bound by professional secrecy, only for preventive medicine, medical diagnosis, care or health service management, and only once notified to the CNPD under article 23, with adequate information security measures.

Comoros Law on the Protection of Personal Data, sensitive personal data

Obtain the Commission's prior authorization and submit to its control before processing biometric data needed to verify a person's identity, data on a person's health or condition, or data on offenses and convictions.

Côte d'Ivoire Law No. 2013-450 on the Protection of Personal Data, sensitive categories of personal data

Obtain ARTCI's prior authorization before processing genetic or medical data and related scientific research, an offense, conviction or court-imposed security measure, or biometric data.

Where an exception permits processing that data, obtain ARTCI's authorization and design and carry out the processing under its supervision.

Egypt Egypt Personal Data Protection Law, Sensitive Personal Data and a child's data

Obtain a Personal Data Protection Center license before collecting, storing, transferring, or processing any Sensitive Personal Data, including a biometric, health, genetic, financial, religious, political, or criminal-record identifier, or any data relating to a child.

Eswatini Data Protection Act, 2022, sensitive personal information

Apply to the Eswatini Communications Commission for authorisation before processing sensitive personal information in the public interest, and comply with any conditions the Commission imposes on that authorisation.

Gabon Law No. 025/2023, sensitive categories of personal data and children's data

Before processing personal data for a public-interest research, study or evaluation purpose in the health domain, obtain the APDPVP's authorization, given after the health-research consultative committee opines on your methodology and the necessity and relevance of the data.

Lebanon Law No. 81/2018, Part V, health, genetic identity and sexual-life data

Apply to the Minister of Public Health for that licence before processing health, genetic-identity or sexual-life data, and treat silence for two months from the application as a refusal.

Show the other 15 laws
Lesotho Data Protection Act, 2011, sensitive personal information

Apply to the Data Protection Commission for authorisation before processing sensitive personal information in the public interest, and comply with any conditions the Commission imposes on that authorisation.

Mauritania Loi n° 2017-020, catégories sensibles de données

Get the Authority's prior authorization before processing genetic data, health-related research data, data on criminal offences or convictions, or biometric data.

Monaco Loi sur la Protection des Données Personnelles, données sensibles et mineurs

As an administrative or judicial authority acting in the exercise of your public powers, do not process genetic or biometric data for authentication or identity control without first obtaining the Authority's opinion, and store the raw biometric data separately from any template derived from it.

Morocco Law No. 09-08, sensitive personal data and offense records

Where you process health data solely for preventive medicine, medical diagnosis, care, or health service management under a practitioner's or an equally bound person's professional secrecy, file a declaration with the CNDP rather than seeking its prior authorization.

Niger Loi n° 2022-59, données sensibles, de santé et biométriques

Obtain the HAPDP's prior authorization before any processing of biometric data, and ensure it responds to a specific, justified necessity with safeguards under this law.

North Macedonia Law on Personal Data Protection (LPDP), special categories, a child's consent and biometric, health and genetic data

Get the Agency's prior approval before processing health data, genetic data or biometric data of a person in North Macedonia, including where the processing rests on the data subject's own explicit consent, unless the processing is determined by a law that itself provides safeguards or the genetic data is processed by an expert for preventive medicine, diagnostics or treatment.

Paraguay Ley N° 6534/2020, de Protección de Datos Personales Crediticios

Do not operate a credit-reporting or credit-information business, or otherwise collect, hold or disclose a person's credit data, without meeting this law's registration, disclosure and administrative obligations, on pain of a fine, a suspension, or a closure of the data-processing operation.

Qatar Personal Data Privacy Protection Law, special-nature personal data

An app processing a data category the PDPPL treats as special in nature (ethnic origin, children's data, health, physical or psychological condition, religious creeds, marital relations, or criminal offenses) about an individual in Qatar must obtain permission from the Competent Department; Qatar's PDPPL does not currently name biometric data as its own special-nature category, so an app processing a voiceprint or faceprint should not assume this permission requirement applies without a further check of any ministerial decision that may have added it.

Republic of the Congo Law No. 29-2019, special categories of personal data

Obtain the national commission's prior authorization before processing personal data bearing on genetic data or health research, offence, conviction or security-measure data, or biometric data.

Sao Tome and Principe Lei n.º 03/2016, sensitive categories and suspect records

Where you process health or sex-life data, including genetic data, for preventive medicine, diagnosis, care or health-service management, do so only through a health professional or another person bound by professional secrecy, notify NAPPD of the processing, and secure it with appropriate information-security measures.

Obtain NAPPD's prior authorization before processing sensitive personal data under the public-interest ground, and before processing data on a person suspected of a crime or an administrative offense, or on a penalty, security measure, fine or ancillary sanction imposed on them.

Senegal Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel, catégories sensibles de données

Get the CDP's prior authorization before processing genetic data, health-related research data, data on criminal offences or convictions, or biometric data.

Somalia Data Protection Act, 2023, sensitive personal data and children's consent

Treat biometric data, race, clan or ethnic origin, religious belief, health status, marital status or sex life, and political opinion or affiliation as sensitive personal data, and apply the measures the Data Protection Authority prescribes by regulation for processing it.

Syria Law No. 12 of 2024 on Protection of Electronic Personal Data, sensitive personal data

Do not process sensitive personal data, including a psychological, mental, physical or genetic health condition or a biometric identifier such as a voiceprint or faceprint, without a license or permit from the Personal Data Protection Authority.

Togo Loi n° 2019-014, données sensibles

Obtain the Instance's prior authorization before processing genetic data, health research data, biometric data, or data on criminal offenses, convictions or security measures.

Tunisia Organic Act on the Protection of Personal Data, sensitive categories and minors

Get the INPDP's separate authorization, decided within thirty days, before processing a special category of data under article 14, except health data.

Get the INPDP's authorization before a physician shares health data with a research body, and never keep or use health data beyond the time its purpose requires.

Telephone contact

16 laws, 14 places
PlaceLawWhat it asks, as read here
California Telephonic Sellers Registration Law

If you or your salespersons place a telephone solicitation meeting the criteria in section 17511.1, such as offering a free additional item, a prize or gift conditioned on a purchase or payment, a below-regular-price claim, an interest in gold, silver, gems, minerals, oil, or gas, a loan-arrangement offer, or an upfront fee for a promised credit card, register with the Department of Justice's Consumer Protection Section at least 10 days before doing business in California, filing the information section 17511.4 requires with a $50 fee.

Renew your registration annually with the same $50 fee, and file an addendum within 10 days of a material change to the registered information, or quarterly for a change in salespersons.

+1 more
Canada Telecommunications Act, Unsolicited Telecommunications and the National Do Not Call List

Comply with any order the Commission makes under section 41 prohibiting or regulating the use of a Canadian carrier's telecommunications facilities for unsolicited telecommunications; this power does not reach a commercial electronic message that Canada's Anti-Spam Legislation section 6 already governs.

Delaware Delaware Telemarketing Fraud Act

Unless exempted, obtain a certificate of registration from the Director of the Consumer Protection Unit, post a $50,000 surety bond or letter of credit, and pay the $100 administrative fee before transacting business with a Delaware customer as a telemarketing seller or telemarketing business; a corporation traded on a public exchange or its at least 60-percent-owned subsidiary, a 501(c)(3) or (6) nonprofit organized or qualified in Delaware, a telemarketing business under contract for such a corporation, and the other sellers 6 Del. C. § 2503A(g) lists need not register.

Florida Florida Telemarketing Act

Obtain a Department of Agriculture and Consumer Services license before doing business in this state as a commercial telephone seller or salesperson, on a written application accompanied by a bond, letter of credit, or certificate of deposit and a $1,500 fee, and do not employ or be affiliated with an unlicensed salesperson or commercial telephone seller.

Germany Gesetz gegen den unlauteren Wettbewerb, Documentation of Consent to Telephone Advertising

Produce the documentation to the competent administrative authority (the Bundesnetzagentur) without delay on request.

Maryland Maryland Telephone Consumer Protection Act

Do not violate the federal Telemarketing and Consumer Fraud and Abuse Prevention Act as implemented by the Federal Trade Commission's Telemarketing Sales Rule, or the federal Telephone Consumer Protection Act as implemented by the Federal Communications Commission's telemarketing and telephone solicitation rules; either violation is independently unlawful, and independently actionable, under Maryland law.

Montana Montana Telemarketing Registration and Fraud Prevention Act

Before telemarketing to a Montana consumer (a telephone campaign to induce a purchase that involves more than one call to the consumer), register annually with the Montana Department of Justice and post a $50,000 surety bond or an equal certificate of deposit, cash or government bond, unless exempt: among others, a business-to-business sale, a consumer with an existing business relationship with or previous purchase from the business, a noncommercial solicitation, or a licensed securities, insurance or real estate professional or supervised financial organization.

Nevada Nevada Solicitation by Telephone Act

If you solicit or cause to be solicited, by telephone or by a device for automatic dialing and announcing, a sale of goods or services or a donation that promises a free premium or prize, offers precious metals, gems, or an oil, gas, mineral or other investment opportunity, sells sporting-event information, offers a recovery service, or responds to inquiries you generated by telling the recipient they were specially selected, register as a seller, and as a salesperson if you communicate with consumers on the seller's behalf, with the Consumer Affairs Unit, post the required bond, letter of credit or certificate of deposit, and pay the registration fee, before doing business, whether you call from a location in Nevada or call into Nevada from elsewhere.

New Hampshire New Hampshire Automatic Telephone Dialing Systems and Caller Identification Services Act

Before using an automatic telephone dialing system, equipment that stores or produces numbers to call randomly or sequentially and delivers a prerecorded message without a live operator, for solicitation in New Hampshire, register with the consumer protection and antitrust bureau of the department of justice at least 10 business days beforehand and pay the annual fee.

New Hampshire New Hampshire Telemarketing Sales Calls Act

If the Federal Trade Commission's Telemarketing Sales Rule binds you, or would bind you if your calls were interstate, comply with it for telemarketing sales calls made within New Hampshire as well.

Show the other 6 laws
Oklahoma Commercial telephone seller registration and unlawful telemarketing practices

Before making a commercial telephone solicitation call or message to a person in Oklahoma, register as a commercial telephone seller with the Attorney General at least ten days beforehand and file a $10,000.00 surety bond, unless an exemption in Section 775A.2 applies to you.

Oregon Oregon Registration of Telephonic Sellers

If you cause or attempt a telephone solicitation of a business opportunity, or represent that a buyer will receive additional units without further cost or a prize or gift for buying or paying, a below-market price because of an unusual event or imminent price increase, or a seller, manufacturer or supplier other than the real one, or you sell gold, silver, other precious metals, precious stones, or an interest in oil, gas or a mineral field, well or exploration site by telephone, register with the Department of Justice at least 10 days before doing business in Oregon and pay the $400 annual fee, whether you call from Oregon or into Oregon.

Pennsylvania Telemarketer Registration Act

Register with the Office of Attorney General, with a $50,000 surety bond, at least 30 days before offering consumer goods or services for sale, and before you or your telemarketers initiate or receive a telemarketing call or message with a Pennsylvania subscriber, unless an exemption applies (among others, a business licensed by or registered with a federal or Commonwealth agency acting within that licence, a qualifying catalog seller, an established business-to-business seller, or a seller calling its own past purchasers after three years under one name).

Texas Automatic Dial Announcing Devices

Before using an automated dial announcing device to make a call that originates or terminates in Texas, obtain a Public Utility Commission permit, renewed annually, and, before using it to play a recorded message on connection, give written notice of the device to each telecommunications utility over whose system it will be used.

Notify the commission by certified mail at least 48 hours before changing the device's telephone number or physical address.

Texas Telephone Solicitation Business Registration Act

Before making a telephone solicitation (a call or other transmission, a text message included) from a location in Texas or to a purchaser in Texas, register each business location with the Texas Secretary of State on a verified registration statement with a $200 filing fee and $10,000 in security (a bond, letter of credit, or certificate of deposit), renew annually, and file a quarterly addendum listing the salespeople who solicited for you.

Before completing a telephone-solicited sale, give the purchaser the disclosures section 302.202 requires, post the registration certificate at the business location, and do not refer to your compliance with the chapter.

Washington Commercial Telephone Solicitation Act

Register with the Washington Department of Licensing before doing business in the state as a commercial telephone solicitor, whether you solicit from a location in Washington or solicit purchasers located in Washington, and before maintaining or defending a lawsuit here.

Do not have a salesperson solicit purchasers on your behalf while your registration is not current.

Biometric privacy

6 laws, 6 places
PlaceLawWhat it asks, as read here
Armenia Law on Protection of Personal Data, biometric data provisions

An app that captures or stores a voiceprint, faceprint, or other biometric identifier from a person in Armenia must obtain the data subject's consent, unless a law-defined purpose can only be achieved through that processing, and must notify the authorized body before beginning to process biometric data, since Armenia's biometric-data definition does not distinguish by modality or by whether the identifier was derived from a recording.

Bahrain Personal Data Protection Law, biometric data prior authorisation

An app must obtain the Personal Data Protection Authority's prior written authorisation before automatically processing biometric data to verify an individual's identity in Bahrain, and before processing a visual recording used for surveillance purposes; consent alone is not a sufficient basis for either activity.

China Provisions on Security Management of Facial Recognition Technology Application

File with the provincial-level cyberspace administration once the stored facial-information count reaches 100,000 individuals.

Kosovo Law No. 06/L-082 on Protection of Personal Data, use of biometric characteristics

In the private sector, apply the same necessity test, inform employees in writing in advance of the measures and their rights, and submit a detailed description of the proposed measures to the Agency for Information and Privacy before taking them.

Do not implement a private-sector biometric measure until the Agency has authorised it, which the Agency must decide within thirty days of receiving your submission.

Malta GDPR Article 9 and Cap. 586, Genetic, Biometric and Health Data Research Processing in Malta

Consult with, and obtain prior authorization from, the IDPC before processing genetic, biometric, or health data of a person in Malta for statistical or research purposes in the public interest, under Cap. 586.

Oman Personal Data Protection Law, biometric and sensitive data prior permit

An app must obtain a Ministry permit before processing biometric data, including a faceprint or voiceprint, about an individual in Oman; the Data Subject's consent alone is not a sufficient basis, and the permit's own conditions sit in Executive Regulations not yet confirmed at primary source.

Data subject rights

2 laws, 2 places
PlaceLawWhat it asks, as read here
Bolivia Constitución Política del Estado, Acción de Protección de Privacidad

A court ordering disclosure, deletion, or rectification under this action must be obeyed immediately, without waiting on the automatic constitutional review.

Burkina Faso Personal Data Protection Law, automated decisions

Obtain a CIL authorization before using an automated decision-support tool that profiles a person or relies on artificial intelligence techniques for predictive purposes in an administrative or private decision.

Breach notification

1 law, 1 place
PlaceLawWhat it asks, as read here
Zimbabwe Cyber and Data Protection Regulations 2024, security breach notification

Answer the Authority's information request about a data breach within 14 days of that request, and cooperate with its enquiries or investigations.

Commercial messages

1 law, 1 place
PlaceLawWhat it asks, as read here
European Union ePrivacy Directive

For unsolicited direct marketing by means other than an automated calling machine, fax, or electronic mail, chiefly a live telephone call, check the Member State's own transposition: each state independently chooses whether such contact needs the recipient's prior consent or only needs to honour a recipient's objection.

Cross border transfer

1 law, 1 place
PlaceLawWhat it asks, as read here
Gabon Law No. 025/2023, interconnection and cross-border transfer of personal data

Obtain the APDPVP's authorization before interconnecting your data systems with those of another public-service body pursuing a different public interest, or with another private party's systems pursuing a different main purpose.

Full text of the NIST Privacy Framework, public domain (a US government work). Every control of the framework.