Privacy Regulation Database
A reference of privacy regulations tracked by the Fine Tracker. Regulations are grouped by jurisdiction type.
Supranational
Digital Markets Act
DMAJurisdiction: European Union
Effective: 5/2/2023
Authority: European Commission
Max Fine: Up to 10% of annual global turnover (20% for repeat offenders)
EU regulation targeting large online platforms designated as gatekeepers. Imposes obligations on core platform services.
Digital Services Act
DSAJurisdiction: European Union
Effective: 2/17/2024
Authority: Digital Services Coordinators + European Commission (for VLOPs)
Max Fine: Up to 6% of annual global turnover
EU regulation on digital services establishing transparency and accountability obligations for online platforms.
EU AI Act
AI ActJurisdiction: European Union
Effective: 8/1/2024
Authority: National AI supervisory authorities + European AI Office
Max Fine: Up to €35M or 7% of annual global turnover for prohibited AI
EU regulation on artificial intelligence. Risk-based framework with strict rules for high-risk AI systems and prohibitions on certain AI practices.
EU ePrivacy Directive
ePrivacyJurisdiction: European Union
Effective: 7/12/2002
Authority: National Data Protection Authorities
Max Fine: Determined by member states
EU directive on privacy in electronic communications. Governs cookies, direct marketing, and confidentiality of communications. Often enforced alongside GDPR.
General Data Protection Regulation
GDPRJurisdiction: European Union
Effective: 5/25/2018
Authority: National Data Protection Authorities (DPAs)
Max Fine: Up to €20M or 4% of annual global turnover
EU-wide data protection law governing the processing of personal data of individuals in the EU/EEA. Sets strict requirements for consent, data subject rights, breach notification, and cross-border transfers.
Key Articles
Art. 5: Principles of processing
Art. 6: Lawful basis
Art. 7: Conditions for consent
Art. 9: Special categories
Art. 15: Right of access
Art. 17: Right to erasure
Art. 20: Data portability
Art. 25: Data protection by design
Art. 32: Security of processing
Art. 33: Breach notification to authority
Art. 35: Data protection impact assessment
Art. 83: Fines and penalties
Art. 12-14: Transparency and information
Art. 44-49: International transfers
Federal
Act on the Protection of Personal Information
APPIJurisdiction: Japan
Effective: 5/30/2003
Authority: Personal Information Protection Commission (PPC)
Max Fine: Up to JPY 100M (~K) for corporations
Japan comprehensive data protection law. Amended in 2020 and 2022 with strengthened individual rights and cross-border transfer rules.
Brazil General Data Protection Law
LGPDJurisdiction: Brazil
Effective: 9/18/2020
Authority: National Data Protection Authority (ANPD)
Max Fine: Up to 2% of revenue, capped at R$50M per violation
Brazil's comprehensive data protection law, modeled on GDPR.
Cable Communications Policy Act (Cable Privacy)
CCPA-CableJurisdiction: United States
Effective: 10/30/1984
Authority: FCC / Private right of action
Max Fine: Actual damages (minimum ,000) plus punitive damages
Protects cable TV subscriber privacy. Requires notice and consent before collecting or disclosing personally identifiable information about subscribers viewing habits.
CAN-SPAM Act
CAN-SPAMJurisdiction: United States
Effective: 12/16/2003
Authority: Federal Trade Commission (FTC)
Max Fine: Up to ,120 per email in violation
Sets rules for commercial email. Requires accurate headers, clear identification as ads, opt-out mechanisms, and physical postal address. Does not require opt-in consent (unlike GDPR).
Children's Online Privacy Protection Act
COPPAJurisdiction: United States
Effective: 4/21/2000
Authority: Federal Trade Commission (FTC)
Max Fine: Up to $50,120 per violation (adjusted for inflation)
US federal law protecting children under 13 online. Requires verifiable parental consent before collecting personal information from children.
Key Articles
§312.2: Definitions
§312.3: Regulation of unfair/deceptive acts
§312.4: Notice requirements
§312.5: Parental consent
§312.6: Right to review
§312.7: Prohibition against conditioning
§312.8: Confidentiality and security
§312.10: Data retention and deletion
China Personal Information Protection Law
PIPLJurisdiction: China
Effective: 11/1/2021
Authority: Cyberspace Administration of China (CAC)
Max Fine: Up to RMB 50M (~M) or 5% of annual revenue
China comprehensive personal information protection law. Strict cross-border transfer restrictions. Applies extraterritorially to processing of Chinese residents data.
Digital Personal Data Protection Act
DPDPA-IndiaJurisdiction: India
Effective: 8/11/2023
Authority: Data Protection Board of India
Max Fine: Up to INR 250 crore (~M)
India comprehensive data protection law. Enforcement beginning 2025. Applies to processing of digital personal data within India and outside India if processing is for offering goods/services to Indian data principals.
Driver Privacy Protection Act
DPPAJurisdiction: United States
Effective: 9/13/1994
Authority: Department of Justice / Private right of action
Max Fine: ,500 per violation plus actual damages
Protects personal information in state motor vehicle records. Restricts disclosure of driver information by state DMVs and authorized recipients.
Electronic Communications Privacy Act
ECPAJurisdiction: United States
Effective: 10/21/1986
Authority: Department of Justice
Max Fine: Criminal fines and up to 5 years imprisonment
Extends government restrictions on wiretaps to include electronic data transmissions. Includes the Wiretap Act (Title I), Stored Communications Act (Title II), and Pen Register Act (Title III).
Fair Credit Reporting Act
FCRAJurisdiction: United States
Effective: 10/26/1970
Authority: FTC / CFPB
Max Fine: Statutory damages up to ,000 per violation; actual damages; punitive damages
Promotes accuracy, fairness, and privacy of consumer information in credit reporting agency files. Gives consumers the right to dispute inaccurate information and limits who can access credit reports.
Family Educational Rights and Privacy Act
FERPAJurisdiction: United States
Effective: 8/21/1974
Authority: Department of Education
Max Fine: Loss of federal funding
Protects privacy of student education records. Gives parents rights over their children records until age 18 or enrollment in post-secondary education. Schools must have consent before disclosing personally identifiable information.
Key Articles
§99.3: Definitions
§99.10: Right to inspect records
§99.20: Right to amend records
§99.30: Consent for disclosure
§99.31: Disclosure exceptions
§99.33: Redisclosure limitations
FTC Act Section 5
FTC ActJurisdiction: United States
Effective: 9/26/1914
Authority: Federal Trade Commission (FTC)
Max Fine: No statutory maximum; consent orders with monetary penalties
Prohibits unfair or deceptive acts or practices in commerce. The FTC's primary authority for privacy enforcement, used when companies break privacy promises or fail to secure data.
Key Articles
Section 5(a): Unfair or deceptive acts prohibited
Section 5(b): FTC enforcement proceedings
Gramm-Leach-Bliley Act
GLBAJurisdiction: United States
Effective: 11/12/1999
Authority: FTC / Federal banking regulators
Max Fine: Up to ,000 per violation; criminal penalties up to ,000 and 5 years
Requires financial institutions to explain data-sharing practices and to safeguard sensitive data. Includes the Safeguards Rule requiring security programs and the Privacy Rule requiring privacy notices.
Key Articles
§501: Protection of nonpublic personal information
§502: Obligations for financial institutions
§521: Privacy of consumer financial information
Title V: Privacy
Health Breach Notification Rule
HBNRJurisdiction: United States
Effective: 9/24/2009
Authority: Federal Trade Commission (FTC)
Max Fine: Up to $50,120 per violation per day
FTC rule requiring vendors of personal health records and related entities to notify consumers and the FTC of breaches of unsecured health information.
Key Articles
§318.1: Purpose and scope
§318.2: Definitions
§318.3: Breach notification requirement
§318.4: Timeliness
§318.5: Methods of notice
§318.6: Content of notice
Health Insurance Portability and Accountability Act
HIPAAJurisdiction: United States
Effective: 8/21/1996
Authority: Department of Health and Human Services (HHS) Office for Civil Rights
Max Fine: Up to $1.5M per violation category per year; criminal penalties up to $250K and 10 years
US federal law protecting health information. Privacy Rule governs use and disclosure of protected health information (PHI) by covered entities and business associates.
Key Articles
Privacy Rule: Use and disclosure of PHI
Security Rule: Administrative, physical, technical safeguards
Enforcement Rule: Compliance and penalties
Breach Notification Rule: Notification requirements for breaches
Personal Data Protection Act
PDPA-SingaporeJurisdiction: Singapore
Effective: 10/15/2012
Authority: Personal Data Protection Commission (PDPC)
Max Fine: Up to SGD 1M (~K) or 10% of annual turnover
Singapore comprehensive data protection law with Do Not Call Registry.
Personal Data Protection Law
PDPLJurisdiction: Saudi Arabia
Effective: 9/14/2023
Authority: Saudi Data & AI Authority (SDAIA)
Max Fine: Up to SAR 5M (~.3M)
Saudi Arabia comprehensive data protection law, heavily influenced by GDPR.
Personal Information Protection and Electronic Documents Act
PIPEDAJurisdiction: Canada
Effective: 4/13/2000
Authority: Office of the Privacy Commissioner of Canada
Max Fine: Up to CAD ,000 per violation
Canada federal private-sector privacy law. Based on 10 fair information principles. Being replaced by Consumer Privacy Protection Act (CPPA).
Privacy Act 1988
Australian Privacy ActJurisdiction: Australia
Effective: 12/14/1988
Authority: Office of the Australian Information Commissioner (OAIC)
Max Fine: Up to AUD 50M or 30% of turnover
Australia comprehensive privacy law. 13 Australian Privacy Principles (APPs). Major reform package pending with significantly increased penalties.
Privacy Act 2020
NZ Privacy ActJurisdiction: New Zealand
Effective: 12/1/2020
Authority: Office of the Privacy Commissioner
Max Fine: Up to NZD ,000 per offense
New Zealand comprehensive privacy law replacing the 1993 Privacy Act. 13 information privacy principles.
Protection of Personal Information Act
POPIAJurisdiction: South Africa
Effective: 7/1/2020
Authority: Information Regulator
Max Fine: Up to ZAR 10M (~K) or imprisonment up to 10 years
South Africa comprehensive data protection law modeled on GDPR.
South Korea Personal Information Protection Act
PIPAJurisdiction: South Korea
Effective: 9/30/2011
Authority: Personal Information Protection Commission (PIPC)
Max Fine: Up to 3% of related revenue
South Korea comprehensive data protection law. One of the strictest in Asia with significant penalties.
Telephone Consumer Protection Act
TCPAJurisdiction: United States
Effective: 12/20/1991
Authority: Federal Communications Commission (FCC)
Max Fine: -,500 per violation
Restricts telemarketing calls, auto-dialed calls, prerecorded and artificial voice messages, and text messages. Requires prior express consent for marketing communications.
UK Data Protection Act 2018
UK DPAJurisdiction: United Kingdom
Effective: 5/25/2018
Authority: Information Commissioner's Office (ICO)
Max Fine: Up to £17.5M or 4% of annual global turnover
UK implementation of GDPR (post-Brexit: UK GDPR). Supplemented by Data Protection Act 2018.
Video Privacy Protection Act
VPPAJurisdiction: United States
Effective: 11/5/1988
Authority: Private right of action
Max Fine: Actual damages (minimum ,500) plus punitive damages and attorney fees
Protects consumer privacy with respect to video rental and streaming records. Prohibits disclosure of personally identifiable rental/streaming information without written consent.
State & Provincial
California Consumer Privacy Act / California Privacy Rights Act
CCPA/CPRAJurisdiction: California
Effective: 1/1/2020
Authority: California Privacy Protection Agency (CPPA) / California Attorney General
Max Fine: Up to $7,500 per intentional violation; $2,500 per unintentional
California state law giving consumers rights over their personal data including right to know, delete, opt-out of sale, and non-discrimination. CPRA (2023) added the California Privacy Protection Agency.
Key Articles
§1798.100: Right to know
§1798.105: Right to delete
§1798.110: Right to disclosure
§1798.115: Right to opt-out of sale
§1798.120: Right to opt-out
§1798.125: Non-discrimination
§1798.130: Notice and request procedures
§1798.135: Do Not Sell link
§1798.140: Definitions
§1798.155: Administrative fines
Colorado Privacy Act
CPAJurisdiction: Colorado
Effective: 7/1/2023
Authority: Colorado Attorney General
Max Fine: Up to $20,000 per violation
Colorado state privacy law with consumer rights and controller obligations.
Connecticut Data Privacy Act
CTDPAJurisdiction: Connecticut
Effective: 7/1/2023
Authority: Connecticut Attorney General
Max Fine: Up to $5,000 per violation
Connecticut state privacy law with consumer data rights and business obligations.
Delaware Personal Data Privacy Act
DPDPAJurisdiction: Delaware
Effective: 1/1/2025
Authority: Delaware Attorney General
Max Fine: Up to ,000 per violation
Delaware comprehensive privacy law.
Illinois Biometric Information Privacy Act
BIPAJurisdiction: Illinois
Effective: 10/3/2008
Authority: Private right of action
Max Fine: ,000-,000 per violation (private lawsuits)
Most aggressive US biometric privacy law. Requires informed written consent before collecting biometric identifiers. Private right of action has generated billions in settlements (Meta M, Google M, TikTok M).
Indiana Consumer Data Protection Act
INCDPAJurisdiction: Indiana
Effective: 1/1/2026
Authority: Indiana Attorney General
Max Fine: Up to ,500 per violation
Indiana comprehensive privacy law effective January 2026.
Iowa Consumer Data Protection Act
ICDPAJurisdiction: Iowa
Effective: 1/1/2025
Authority: Iowa Attorney General
Max Fine: Up to ,500 per violation
Iowa comprehensive privacy law. Business-friendly approach.
Minnesota Consumer Data Privacy Act
MCDPAJurisdiction: Minnesota
Effective: 7/31/2025
Authority: Minnesota Attorney General
Max Fine: Up to ,500 per violation
Minnesota comprehensive privacy law with strong profiling protections.
Montana Consumer Data Privacy Act
MTCDPAJurisdiction: Montana
Effective: 10/1/2024
Authority: Montana Attorney General
Max Fine: Up to ,500 per violation
Montana comprehensive privacy law.
New Jersey Data Privacy Act
NJDPAJurisdiction: New Jersey
Effective: 1/15/2025
Authority: New Jersey Attorney General
Max Fine: Up to ,000 per first violation; ,000 per subsequent
New Jersey comprehensive privacy law effective January 2025. Includes strong protections for children and teens.
Oregon Consumer Privacy Act
OCPAJurisdiction: Oregon
Effective: 7/1/2024
Authority: Oregon Attorney General
Max Fine: Up to $7,500 per violation
Oregon state privacy law with broad definition of personal data and strong consumer rights.
Tennessee Information Protection Act
TIPAJurisdiction: Tennessee
Effective: 7/1/2025
Authority: Tennessee Attorney General
Max Fine: Up to ,500 per violation
Tennessee comprehensive privacy law.
Texas Data Privacy and Security Act
TDPSAJurisdiction: Texas
Effective: 7/1/2024
Authority: Texas Attorney General
Max Fine: Up to $7,500 per violation
Texas comprehensive privacy law. Applies to entities conducting business in Texas or producing products/services consumed by Texas residents.
Utah Consumer Privacy Act
UCPAJurisdiction: Utah
Effective: 12/31/2023
Authority: Utah Attorney General
Max Fine: Up to $7,500 per violation
Utah state privacy law. Business-friendly approach with consumer rights to access, delete, and opt-out.
Virginia Consumer Data Protection Act
VCDPAJurisdiction: Virginia
Effective: 1/1/2023
Authority: Virginia Attorney General
Max Fine: Up to $7,500 per violation
Virginia state comprehensive privacy law. Gives consumers rights to access, correct, delete, and opt-out of sale of personal data.