Regulatory Focus
Data Protection

Data Protection
195
Countries Covered
28
Languages
2367
Regulatory Sources
To take advantage of the significant opportunities the Internet of Things (IoT) presents, companies must navigate a growing web of rules addressing cybersecurity risks, data protection, wireless connectivity, software security, product labeling, and market access for connected devices across jurisdictions.
Data protection and privacy regulations establish rules governing the collection, storage, deletion, sharing, and safeguarding personal data, while also defining individuals’ rights and accountability obligations for organizations.
Companies typically need to put governance, technical, and organizational measures in place to ensure personal data is collected, stored, shared, and transferred in a lawful, fair, and secure manner. Obligations contained in data protection laws commonly cover transparency, accountability, data security, respect for individual rights, safeguards for cross-border data transfers, etc.
Privacy regulations typically focus on the following, inter alia:
- Fair and lawful data processing (including collection, storage, deletion, use, sharing, etc.)
- Personal data classification and data quality
- Data minimisation
- Data security
- Privacy by design and by default
- Rights of individuals (data subjects)
- Data breach reporting
- Cross-border data transfers
We cover national and regional personal data protection regulations, both proposed and enacted, that establish how personal data may be collected, stored, shared, transferred, or otherwise processed, alongside rules strengthening individual rights and accountability obligations for organizations. Our coverage also includes laws addressing privacy and security considerations for connected products and digital technologies across global markets.
Examples of regulations within our coverage:
- EU: Protection of Individuals with Regard to the Processing of Personal Data and the Free Movement of Such Data, Regulation, (EU) 2016/679
- UK: Data Protection Act, 2018
- Norway: Personal Data Protection Act, No. 38, 2018
- Brazil: Protection of Personal Data, Law No. 13709/2018
- California (USA): Privacy of Personal Information, Assembly Bill 375, Enacted, 2018
- California (USA): Connected Devices, Privacy and Consumer Protection, Senate Bill 327 Enacted, 2018
- New Zealand: Privacy Act No. 31, 2020
- Canada: Personal Information Protection and Electronic Documents Act, 2000
- China: Personal Information Protection Law, 2021
- Kenya: Data Protection Act, No. 24, 2019
- India: Digital Personal Data Protection Act, 2023
Experts in this Area

Intelligent Resources
Automate the work of managing regulatory change.
Let AI agents do the heavy lifting of monitoring regulations, mapping requirements to products, extracting obligations, and surfacing the risks that need attention first.
Monitor Product Compliance
Stay Ahead of Regulatory Change
Get early visibility into changes that could affect your products, supply chain, or market access—so you can act proactively, not reactively.
Assess Regulatory Applicability
Map Regulations to Your Products
Eliminate manual research and cut through regulatory noise by surfacing only the requirements relevant to your business, markets, and product categories.
Identify Compliance Requirements
Turn complex regulations into clear, actionable tasks.
Give your teams instant clarity as AI agents transform dense legal and regulatory text into structured, easy-to-understand requirements.
Prioritize Business Risk
Focus Where Risk Is Highest
Make faster, risk-informed decisions with confidence as AI agents automatically rank regulatory changes based on urgency, business impact, compliance deadlines, and product exposure.
Spotlight
Turning Compliance into Value

The State of Product
Compliance 2026
Discover how 500+ global leaders are shifting product compliance from a cost-centre into a strategic driver of growth, with key benchmarks like 69% of teams calling remediation their biggest challenge.
Frequently Asked Questions
-
Organizations that process (collect, share, store, transfer, etc.) personal data of individuals are typically in scope – often regardless of where the organization is established. For example, laws such as the EU GDPR and Brazil’s LGPD, apply extraterritorially when activities involve offering goods or services to individuals or monitoring their behavior in the jurisdiction from which the law originates.
-
Companies must ensure lawful, fair, and transparent processing of personal data, respect and enable individuals’ rights (such as access, correction, and deletion), implement appropriate technical and organizational security measures, and manage cross-border data transfers in line with applicable safeguards and restrictions.
-
No. Consent is one lawful basis for personal data processing, but other bases may be more appropriate in certain cases – for example, performance of a contract, legal obligation, legitimate interests of an organisation, etc. It is also important to note that, according to many laws (including the EU GDPR), consent shall be freely given, specific, informed and unambiguous; and individuals have the right to withdraw consent at any time (although this does not affect the lawfulness of processing based on consent before its withdrawal).
-
Common penalties typically include administrative fines (sometimes tied to annual turnovers, such as under the EU GDPR) and corrective measures (e.g. orders to bring data processing into compliance, warnings, suspension of data processing or data transfers, and orders for deletion of personal data). In some jurisdictions, privacy law violations may result in criminal penalties and imprisonment. In addition, many countries allow individuals to bring civil actions against organisations, which can lead to damages being awarded.



