Privacy worldwide

100 countries, sorted by the privacy their laws provide.

Grouped into seven tiers, from constitutional limits on the state down to pervasive surveillance. Not a ranking — a tier is a range, and the order within one carries no meaning. Two tables, two directions — protection from the state, and protection from companies — and a country can rank high on one while low on the other.

How to read this. Every country sits in one of seven tiers by how much privacy its law provides in practice — not by how much surveillance it runs. The table has two kinds of rows. Documented rows trace cell‑by‑cell to a primary instrument — a constitution, a statute, a court ruling, an adequacy decision — and those cells carry a source number. The rest are estimates, placed from a cross‑country internet‑freedom index with no per‑country privacy document behind them; they are shown in grey, without a number, on purpose. Scores were dropped deliberately: tiers are far more defensible than any exact rank. Policies change — verify current details before relying on this. General information, not legal advice.

Checked July 11, 2026

How the tiers work

Seven tiers, strongest to weakest

The tiers describe the level of privacy protection a person effectively has, end to end. The meter shows the tier at a glance — more filled bars mean more protection. The columns carry the mechanism — whether the protection is constitutional or merely statutory, whether retention is mandatory, whether encryption can be compelled.

  • Comprehensive protections. A data-protection statute plus a constitutional court that has actually struck surveillance powers down — protection that survives a change of government.
  • Strong protections. Robust statutory rights and an active regulator; any bulk-collection or retention power is limited, contested, or under judicial pressure.
  • Substantial protections. Solid data-protection law and enforcement, but with a standing retention mandate or an intelligence power that isn’t fully checked.
  • Moderate protections. Real law on the books, weaker enforcement, and state-access powers that cut against it.
  • Limited protections. Sweeping retention or bulk powers, or a compelled-assistance regime, outweigh the statutory protections that exist.
  • Weak protections. Broad state access and thin oversight; the law itself does little to constrain surveillance.
  • Minimal protections. Pervasive state surveillance, localization or interception mandates, and little or no independent oversight.

The tags under a country

Five, Nine, and Fourteen Eyes

A handful of countries carry a small slate tag — Fourteen Eyes — beneath their name. These name an intelligence-sharing arrangement that grew out of a postwar signals-intelligence pact, in which the member states share the communications their agencies intercept. It is one club in three rings, not three separate ones: each wider ring contains the one inside it.

  1. 5Five Eyes

    The original core — the United States, the United Kingdom, Canada, Australia, and New Zealand.

  2. 9Nine Eyes

    The Five, plus Denmark, France, the Netherlands, and Norway.

  3. 14Fourteen Eyes

    The Nine, plus Germany, Belgium, Italy, Spain, and Sweden.

So the rings nest. Whatever the innermost Five share reaches the Nine and the Fourteen as well — the wider the ring, the more governments see the same intercept. A country’s tag marks the ring it enters at: the smallest circle that already includes it, which is why a partner such as France reads Nine Eyes rather than Five.

That is why the tag belongs on a privacy page. A member can receive what its partners collect, so communications a country’s own courts might forbid it to gather can still reach its agencies through an ally — which is what caps how high an otherwise-strong democracy can sit in the tables below. The fuller version of that argument is at the foot of the page.

Membership is documented through declassified records of the UKUSA arrangement and reporting on leaked intelligence files, rather than any single public statute; it is shown here as background, not as a rated cell. Checked July 11, 2026.

The first table

100 countries, rated against the state

Filter by tier, or sort A–Z. Each marker reads on a single scale — the more filled the shape, the more protection — and works in greyscale. Grey markers are estimates; coloured markers with a number are documented.

Protection from the state100 countries · sort by tier or A–Z
Tier Sort
CountryProtection from the stateLegal basisData retentionMessage scanningEncryptionBiometricEnforcementEU adequacyTrendBasis
ESTEstoniaEuropeComprehensiveConstitutional1Targeted2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableP·I
ISLIcelandEuropeComprehensiveGDPR (EEA)1NoneVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EEAFreest (FOTN)12I
DEUGermanyEurope Fourteen EyesComprehensiveConstitutional1,4,5None in force2,4Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUCourts active4,5P
AUTAustriaEuropeComprehensiveGDPR · DSG1Court-struck2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableP
PRTPortugalEuropeComprehensiveConstitutional1Court-struck ’222Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUPost-strikeP
SVNSloveniaEuropeComprehensiveGDPR · ZVOP-21Court-struck2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableI
FINFinlandEuropeComprehensiveConstitutional1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableP·I
IRLIrelandEuropeComprehensiveGDPR1Targeted (post-DRI)2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Weak enforcementEUStableP
CRICosta RicaAmericasComprehensiveConstitutionalTargetedNo scanning regimeNo compulsionRestrictedAgencyStableI
CHLChileAmericasComprehensiveConstitutionalTargetedNo scanning regimeNo compulsionRestrictedNew agencyNew GDPR-style lawP·I
JPNJapanAsia–PacificComprehensiveAPPI14TargetedNo scanning regimeNo compulsionRestrictedPPC14Adequacy3StableP·I
URYUruguayAmericasComprehensiveLey 18.331TargetedNo scanning regimeNo compulsionRestrictedURCDPAdequacy3StableI
LUXLuxembourgEuropeComprehensiveGDPR1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1CNPD1EUStableI
CHESwitzerlandEuropeComprehensiveConst · FADP6Mandatory ~6mo6No scanning regimeDecryption (proposed)6Not locatedFDPIC6Adequacy3OSCPT revision; Proton exit6P
CZECzechiaEuropeStrongGDPR1Court-struck2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableP
NLDNetherlandsEurope Nine EyesStrongGDPR · UAVG1Struck ’152Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EU9 EyesP
NORNorwayEurope Nine EyesStrongGDPR (EEA)1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EEA9 EyesP·I
TWNTaiwanAsia–PacificStrongPDPATargetedNo scanning regimeNo compulsionRestrictedNew PDPCNew DPA (2025)P·I
BELBelgiumEurope Fourteen EyesStrongGDPR1Re-legislatedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EU14 EyesP
ESPSpainEurope Fourteen EyesStrongLOPDGDD1Mandatory (contested)Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1AEPD · active1EU14 EyesP
DNKDenmarkEurope Nine EyesStrongGDPR1Session loggingVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EURetention revivalP·I
NZLNew ZealandAsia–Pacific Five EyesStrongPrivacy Act 2020TargetedNo scanning regimeAssistance regimeRestrictedCommissioner5 EyesP·I
FRAFranceEurope Nine EyesStrongGDPR1Mandatory (nat-sec)Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1CNIL · active1EULQDN II reopened retention2P
LTULithuaniaEuropeStrongGDPR1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1VDAI1EUStableI
LVALatviaEuropeStrongGDPR1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1DVI1EUStableI
ARGArgentinaAmericasStrongLey 25.326TargetedNo scanning regimeNo compulsionRestrictedAAIPAdequacy3StableP·I
ITAItalyEurope Fourteen EyesStrongGDPR1Up to 72moVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Garante · active1EU14 EyesP
SWESwedenEurope Fourteen EyesStrongGDPR1Mandatory · FRAVoluntary (CC 1.0)19,20Backdoor push ’25Restricted (GDPR)1Independent1EUFRA + encryption billP
POLPolandEuropeSubstantialGDPR1Mandatory 12moVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Broad police accessEUOversight gapsP·I
CANCanadaAmericas Five EyesSubstantialPIPEDATargetedNo scanning regimeLawful-access billsRestrictedOPCAdequacy3Lawful-access billsP·I
GRCGreeceEuropeSubstantialGDPR1MandatoryVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Predator scandalEUPredator affairP·I
HRVCroatiaEuropeSubstantialGDPR1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1AZOP1EUStableI
CYPCyprusEuropeSubstantialGDPR1ContestedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Commissioner1EUStableI
SVKSlovakiaEuropeSubstantialGDPR1Court-struck2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableI
BRABrazilAmericasSubstantialLGPD13Marco CivilNo scanning regimeNo compulsionLGPD-restrictedANPD13Adequacy ’2613,3EU adequacy (2026)13P·I
MLTMaltaEuropeSubstantialGDPR1TargetedVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1IDPC1EUStableI
ROURomaniaEuropeSubstantialGDPR1Repeatedly struck2Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableP·I
BGRBulgariaEuropeSubstantialGDPR1Struck ’152Voluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Independent1EUStableI
ZAFSouth AfricaAfricaSubstantialPOPIA · Const §1418RICA (amaBhungane)18No scanning regimeNo compulsionPOPIA-restrictedRegulatorPost-amaBhunganeP
KORSouth KoreaAsia–PacificSubstantialPIPA15MandatoryNo scanning regimeAssistance regimeRestrictedPIPC · active15Adequacy3Content controlsP·I
HUNHungaryEuropeSubstantialGDPR1MandatoryVoluntary (CC 1.0)19,20No compulsionRestricted (GDPR)1Pegasus operatorEUIlliberal driftP·I
GHAGhanaAfricaSubstantialDPA 2012TargetedNo scanning regimeNo compulsionNot locatedCommissionStableI
COLColombiaAmericasModerateLey 1581TargetedNo scanning regimeNo compulsionNot locatedSICStableI
MEXMexicoAmericasModerateLFPDPPPMandatoryNo scanning regimeNo compulsionNot locatedINAI abolished ’25INAI dissolutionP·I
ECUEcuadorAmericasModerateLOPDP 2021TargetedNo scanning regimeNo compulsionNot locatedAuthorityNew lawI
ARMArmeniaEurasiaModerateLaw 2015TargetedNo scanning regimeNo compulsionNot locatedAgencyStableI
SRBSerbiaEuropeModerateZZPLMandatoryNo scanning regimeNo compulsionSafe City CCTVCommissionerSmart-city CCTVI
MDAMoldovaEuropeModerateLaw 133TargetedNo scanning regimeNo compulsionNot locatedCentreEU-alignmentI
UKRUkraineEuropeModeratePDP law (wartime)Wartime powersNo scanning regimeNo compulsionNot locatedOmbudsmanWartimeI
MNGMongoliaAsia–PacificModerateLaw 2021TargetedNo scanning regimeNo compulsionNot locatedAuthorityStableI
USAUnited StatesAmericas Five EyesModerateNo federal statute9Provider-retainedVoluntary (providers)21No general mandateState patchworkNo federal DPADPF3§702 / RISAA; broker buys9P
GEOGeorgiaEurasiaModeratePDP lawMandatoryNo scanning regimeNo compulsionNot locatedForeign-agent law↓↓Foreign-influence lawP·I
ISRIsraelMiddle EastModeratePPLMandatoryNo scanning regimeAssistance regimeDeployedPPASurveillance exportsP·I
MYSMalaysiaAsia–PacificModeratePDPA (2024 amd)MandatoryNo scanning regimeAssistance regimeEmergingCommissionerContent controlsI
PHLPhilippinesAsia–PacificModerateDPA 2012TargetedNo scanning regimeNo compulsionEmergingNPCSIM registrationI
NAMNamibiaAfricaModerateBill pendingTargetedNo scanning regimeNo compulsionNot locatedNone yetStableI
BWABotswanaAfricaLimitedDPA 2018TargetedNo scanning regimeNo compulsionNot locatedCommissionStableI
GBRUnited KingdomEurope Five EyesLimitedDUAA 202512mo ICRs7Scanning power (OSA)22TCN power7Live FRICOAdequacy3↓↓IPA · OSA · Apple order7,8,12P
AUSAustraliaAsia–Pacific Five EyesLimitedPrivacy Act 1988Mandatory 24mo10No scanning regimeDecryption (TOLA)10EmergingOAICTOLA, retention10P·I
TUNTunisiaAfricaLimitedLaw 2004-63TargetedNo scanning regimeNo compulsionNot locatedINPDPStableI
SENSenegalAfricaLimitedLaw 2008-12TargetedNo scanning regimeNo compulsionNot locatedCDPStableI
KENKenyaAfricaLimitedDPA 2019TargetedNo scanning regimeNo compulsionEmergingODPCProtest shutdown ’24I
NGANigeriaAfricaLimitedDPA 2023TargetedNo scanning regimeNo compulsionEmergingNDPCNew lawI
ZMBZambiaAfricaLimitedDPA 2021TargetedNo scanning regimeNo compulsionNot locatedAuthorityStableI
IDNIndonesiaAsia–PacificLimitedPDP 2022LocalizationNo scanning regimeAssistance regimeEmergingAuthorityLocalizationI
LKASri LankaAsia–PacificLimitedPDPA 2022TargetedNo scanning regimeNo compulsionNot locatedAuthorityNew lawI
JORJordanMiddle EastLimitedPDP 2023MandatoryNo scanning regimeAssistance regimeNot locatedAuthorityNew lawI
LBNLebanonMiddle EastLimitedLaw 81/2018TargetedNo scanning regimeNo compulsionNot locatedWeakStableI
INDIndiaAsia–PacificLimitedPuttaswamy · DPDP16Localization (emerging)No scanning regimeDecryption (IT §69)Aadhaar16Non-independent board16DPDP state exemptionsP
MARMoroccoAfricaLimitedLaw 09-08MandatoryNo scanning regimeAssistance regimeNot locatedCNDPPegasusI
SGPSingaporeAsia–PacificWeakPDPA 2012MandatoryBroad state accessAssistance regimeNational biometricPDPCHigh state accessP·I
NPLNepalAsia–PacificWeakPrivacy Act 2018TargetedBroad state accessNo compulsionNot locatedNot locatedStableI
PERPeruAmericasWeakLey 29733MandatoryBroad state accessNo compulsionNot locatedANPDStableI
KWTKuwaitMiddle EastWeakCITRA regsMandatoryBroad state accessAssistance regimeEmergingCITRABroad accessI
QATQatarMiddle EastWeakLaw 13/2016MandatoryBroad state accessAssistance regimeBiometric CCTVAuthorityPervasive monitoringI
OMNOmanMiddle EastWeakPDPL 2022MandatoryBroad state accessAssistance regimeEmergingAuthorityBroad exemptionsI
KAZKazakhstanEurasiaWeakLaw 2013SORM modelBroad state accessHTTPS-interceptionTargetEYE FRAuthorityBuildout (incomplete)P·I
UGAUgandaAfricaWeakDPA 2019MandatoryBroad state accessAssistance regimeHuawei CCTVAuthorityPegasus / CCTVI
ZWEZimbabweAfricaWeakDPA 2021MandatoryBroad state accessAssistance regimeFR pilotAuthorityStableI
THAThailandAsia–PacificWeakPDPA 2019MandatoryBroad state accessAssistance regimeDeployedCommitteeContent controlI
KHMCambodiaAsia–PacificWeakSub-decree (NIG)NIG gatewayBroad state accessAssistance regimeDeployedNoneNIG buildoutI
AZEAzerbaijanEurasiaWeakPervasive monitoringMandatoryBroad state accessAssistance regimeNot locatedNonePegasusI
BHRBahrainMiddle EastWeakPDPL 2018MandatoryBroad state accessAssistance regimeBiometric CCTVAuthoritySpywareI
IRQIraqMiddle EastWeakNo comprehensive lawMandatoryBroad state accessAssistance regimeNot locatedNoneShutdownsI
PAKPakistanAsia–PacificMinimalPECA 2016Web Monitoring SystemBroad state accessDe facto compelledDeployedNone↓↓Firewall buildoutI
TURTurkeyEurasiaMinimalKVKKMandatoryBroad state accessAssistance regimeDeployedKVKK boardContent controlP·I
EGYEgyptAfricaMinimalDP Law 2020MandatoryBroad state accessAssistance regimeDeployedRegs pendingMass surveillanceI
VENVenezuelaAmericasMinimalNo independent DPAMandatoryBroad state accessAssistance regimeDeployedNone↓↓CANTV monitoringI
AREUAEMiddle EastMinimalPDPL 2021 (regs unissued)MandatoryBroad state accessDe facto compelledBiometric CCTVAuthoritySpyware, biometricsP·I
SAUSaudi ArabiaMiddle EastMinimalPDPL (state-exempt)LocalizationBroad state accessDe facto compelledBiometric CCTVSDAIAState-exempt enforcementP·I
UZBUzbekistanEurasiaMinimalLaw 2019 (localization)SORM modelBroad state accessDe facto compelledState biometricAuthorityBuildout (incomplete)P·I
VNMVietnamAsia–PacificMinimalPDPD 2023LocalizationBroad state accessDe facto compelledDeployedAuthorityLocalization, controlP·I
CUBCubaAmericasMinimalDecree 370MandatoryBroad state accessDe facto compelledNot locatedState ISP monopolyETECSA monopolyI
BLRBelarusEuropeMinimalNominalSORM · DPIBroad state accessDe facto compelledDeployedNone↓↓Near-total in crisesP·I
RUSRussiaEurasiaMinimalNominalSORM-3 · Yarovaya11State interception11Key disclosure11FR networkNo independent DPA↓↓Sovereign-internet buildout (incomplete)11P
MMRMyanmarAsia–PacificMinimalJunta ruleMandatoryBroad state accessDe facto compelledJunta biometricNone↓↓Junta control (not sealed)12I
IRNIranMiddle EastMinimalNominalMandatoryBroad state accessDe facto compelledDeployedNone↓↓NIN advanced; full shutdowns12P·I
TKMTurkmenistanEurasiaMinimalNominal (2017)TotalBroad state accessDe facto compelledState controlNoneNear-total control12I
CHNChinaAsia–PacificMinimalPIPL (firms)17Real-name · comprehensive12State interception12Backdoor / compelled12Skynet · FR12PIPL on firmsGreat Firewall operational12P
PRKNorth KoreaAsia–PacificMinimalNo open internetTotalBroad state accessIntranet onlyTotal controlNoneKwangmyong only12I

No countries in that tier.

Filled. Strong safeguard — a constitutional right, no or targeted retention, no compelled decryption. Half. Present but qualified — contested, weakly enforced, or an assistance regime. Open ring. Absent, mandatory, or compelled — the low-protection end. Dashed. Not located — we couldn’t find it, which isn’t proof it doesn’t exist. Grey (any shape). Estimated from the index, with no per-country document — shown without a source number.

Reading the columns. Legal basis is whether privacy rests on an enforceable constitutional right, ordinary statute, or little at all. Data retention asks whether communications metadata must be kept — less is more protective. Message scanning is whether the law lets or makes providers inspect the content of private messages without individualized suspicion — a filled marker means no such regime, a half marker means voluntary scanning of non-encrypted surfaces, an open ring means a scanning mandate, client-side scanning, or broad state interception; it is distinct from encryption, which follows. Encryption is whether providers can be compelled to weaken or break it. Biometric is the reach of state facial-recognition and biometric-ID systems — a filled marker means little or none, an open ring means pervasive deployment. How those systems — automated plate readers, face recognition, always-on sensors — actually work is on our cameras & sensors page. Enforcement is whether an independent regulator actually acts. EU adequacy is here because it is the one external, independent verdict on a country’s data-protection regime: the European Commission formally judging it essentially equivalent to the GDPR. It is Euro-centric and many countries never sought it, so a dash is not a demerit — only the positive mark carries weight. Five / Nine / Fourteen Eyes intelligence-sharing appears as a tag under the country name, because it caps how high an otherwise-strong democracy can sit. Basis tags each row: P primary-source-driven, P·I mixed, I estimated from the index. A cell shows a number only where the primary instrument could be linked directly; some documented rows are summarised without a per-cell link.Checked July 11, 2026 — verify current details before relying on this. General information, not legal advice.

The other direction

The same countries, rated against companies

The table above asks how well a country’s law restrains the state. This one asks the opposite: how well it restrains companies — whether you can see what a business holds on you, delete it, refuse the sale of it, and whether a regulator will make that stick. They are different questions, and a country can sit at opposite ends of each.

China is the clearest case. It is in the bottom tier against the state — and near the top against companies, because its Personal Information Protection Law is one of the strictest corporate-data regimes anywhere: separate opt-in consent, deletion and portability rights, hard limits on facial recognition, and fines up to 5% of turnover. The pattern repeats — several authoritarian states bind companies tightly while exempting themselves, and the Five / Nine / Fourteen Eyes democracies, capped in the first table by their intelligence powers, are not capped here, so their commercial-privacy strength shows through. The European Union sits at the top of both.

Same discipline as the first table: documented rows trace to the statute or regulator behind them and carry a source number; estimated rows rest on the DLA Piper cross-country tracker — the commercial-privacy analog to the internet-freedom index used above — and are shown in grey without a number. This is a first tranche: the strongest regimes and the marquee reversals are placed; the weaker-protection countries follow in the next pass. General information, not legal advice.

One company-side practice these columns don’t yet capture: surveillance pricing — being charged a different price based on what a company knows about you. There is little law on it anywhere; the nearest hook is the GDPR’s limit on decisions “based solely on automated processing,” including profiling. We take it apart on the financial privacy page.

  • Comprehensive protections. An omnibus data-protection law binding the private sector, opt-in consent, the full set of individual rights — access, deletion, portability — and an independent regulator that levies real, turnover-scaled fines.
  • Strong protections. A comprehensive law and an active regulator with most rights intact; penalties are real but lower, the regulator isn’t fully independent, or one axis such as consent or ad-targeting is weaker.
  • Substantial protections. Solid law and rights on paper, but enforcement is uneven or under-resourced, or a strengthening reform has stalled.
  • Moderate protections. A law exists — often newer, sectoral, or opt-out — with only partial rights or a young, underpowered regulator.
  • Limited protections. Coverage is narrow or not yet in force, consent rules are weak, and there is little enforcement against companies.
  • Weak protections. Minimal statutory obligations on companies; any regulator is nominal.
  • Minimal protections. No meaningful private-sector data-protection law, or none that is enforced.
Protection from companies100 countries · sort by tier or A–Z
Tier Sort
CountryProtection from companiesComprehensive lawConsent modelAccess & deletionSale & targeted adsSensitive & childrenBreach noticeEnforcement & penaltyEU adequacyTrendBasis
ESTEstoniaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
DEUGermanyEurope Fourteen EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
AUTAustriaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
PRTPortugalEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
SVNSloveniaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
FINFinlandEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
IRLIrelandEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPC · backlogEUStableP
LUXLuxembourgEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
NLDNetherlandsEurope Nine EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
BELBelgiumEurope Fourteen EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
ESPSpainEurope Fourteen EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
DNKDenmarkEurope Nine EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
FRAFranceEurope Nine EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
LTULithuaniaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
LVALatviaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
ITAItalyEurope Fourteen EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
SWESwedenEurope Fourteen EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
CZECzechiaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
POLPolandEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
GRCGreeceEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
HRVCroatiaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
CYPCyprusEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
SVKSlovakiaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
MLTMaltaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
ROURomaniaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
BGRBulgariaEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
HUNHungaryEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EUStableP
ISLIcelandEuropeComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EEAStableP
NORNorwayEurope Nine EyesComprehensiveOmnibus (GDPR)1Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-cat · Art. 872h to DPADPA · up to 4% turnover1EEAStableP
CHESwitzerlandEuropeComprehensiveFADP 202311Opt-inAccess · erase · portConsent requiredSpecial-catMandatoryFDPIC11Adequacy2StableP
KORSouth KoreaAsia–PacificComprehensivePIPA7Opt-in (strict)Access · erase · portConsent requiredStrictMandatoryPIPC · large fines7Adequacy2Active enforcerP
BRABrazilAmericasComprehensiveLGPD5Opt-in · lawful basisAccess · erase · portConsent requiredSpecial-catMandatoryANPD5Adequacy ’265EU adequacy 2026P
JPNJapanAsia–PacificStrongAPPI6Opt-out for sharingAccess · eraseOpt-out (sharing)Special-catMandatory (2022)PPC6Adequacy2StableP
GBRUnited KingdomEurope Five EyesStrongUK GDPR · DUAA ’258Opt-in · lawful basisAccess · erase · portConsent (PECR)Children’s code72h to ICOICO · up to 4%Adequacy2DUAA loosening8P
ARGArgentinaAmericasStrongLey 25.32614Opt-inAccess · rectify · deleteLimited rulesSpecial-catEmergingAAIPAdequacy2Reform pendingP·I
URYUruguayAmericasStrongLey 18.33114Opt-inAccess · deleteLimited rulesSpecial-catEmergingURCDPAdequacy2StableP·I
NZLNew ZealandAsia–Pacific Five EyesStrongPrivacy Act 202014IPPs (consent)Access · correctLimited rulesEmergingNotifiable (2020)CommissionerStableP·I
TWNTaiwanAsia–PacificStrongPDPA14Consent-basedAccess · deleteLimited rulesSpecial-catEmergingNew PDPC (2025)New DPA 2025P·I
CHNChinaAsia–PacificStrongPIPL4Opt-in (separate consent)Access · delete · portConsent requiredStrict (FR limits)MandatoryCAC · up to 5% (state-run)4Strict on firmsP
CANCanadaAmericas Five EyesSubstantialPIPEDA12Consent-basedAccess · correctLimited rulesEmergingMandatory (PIPEDA)OPC · weak fines12Adequacy (comm.)2Reform stalled (C-27)P·I
AUSAustraliaAsia–Pacific Five EyesSubstantialPrivacy Act 198813APPsAccess · correctLimited rulesChildren’s code (2024)Notifiable (NDB)OAIC2024 reforms13P·I
ZAFSouth AfricaAfricaSubstantialPOPIA10Consent-basedAccess · deleteMarketing opt-inSpecial-catMandatoryInfo Regulator10StableP
USAUnited StatesAmericas Five EyesModerateNo federal omnibus · state laws3Opt-out (state)Access · delete (state)Opt-out of sale (CCPA)3COPPA (children)Breach laws (all states)FTC · state AGs · CPPA3DPF2State patchwork growingP
INDIndiaAsia–PacificLimitedDPDP 2023 (rules pending)9Consent (once in force)Access · erase (pending)No opt-out yetParental consentMandatory (pending)Non-independent board9DPDP not yet in forceP
CRICosta RicaAmericasSubstantialLey 8968Opt-inAccess · rectifyLimited rulesSpecial-catEmergingPRODHABStableI
CHLChileAmericasSubstantialLey 21.719Opt-inAccess · erase · portConsent (pending)Special-catMandatory (’26)New APDP (’26)In force Dec 2026I
COLColombiaAmericasSubstantialLey 1581Opt-inAccess · deleteRegistry rulesSpecial-catMandatorySIC · activeActive enforcerI
ECUEcuadorAmericasModerateLOPDP 2021Opt-inAccess · eraseLimited rulesSpecial-catMandatorySuperintendenciaYoung regulatorI
MEXMexicoAmericasModerateLFPDPPPOpt-out (ARCO)ARCO rightsLimited rulesSpecial-catMandatoryExec ministry (non-indep)INAI abolished 2025I
PERPeruAmericasModerateLey 29733Opt-inAccess · deleteLimited rulesSpecial-catEmergingAPDPStableI
VENVenezuelaAmericasWeakNo comprehensive lawNoneHabeas data (const.)NoneNoneNoneNoneStableI
CUBCubaAmericasLimitedDecree-Law 2022ConsentAccessNoneSomeNoneState bodyStableI
SRBSerbiaEuropeSubstantialPDP Law 2018Opt-inAccess · erase · portConsentSpecial-cat72hCommissionerGDPR-alignedI
MDAMoldovaEuropeModeratePDP LawOpt-inAccess · rectifyLimited rulesSpecial-catEmergingNCPDPGDPR alignmentI
UKRUkraineEuropeModerateLaw 2010 (reform pending)ConsentAccess · rectifyWeakSpecial-catNoneOmbudsmanGDPR reformI
BLRBelarusEuropeLimitedPDP Law 2021ConsentAccessWeakSomeNoneState (NPDP)State-alignedI
ARMArmeniaEurasiaModeratePDP Law 2015Opt-inAccess · rectifyWeakSpecial-catNoneAgencyStableI
GEOGeorgiaEurasiaSubstantialPDP Law 2023Opt-inAccess · erase · portConsentSpecial-cat72hPDP ServiceNew 2023 lawI
TURTurkeyEurasiaModerateKVKK 2016Opt-in (explicit)Access · deleteLimited rulesSpecial-catMandatoryKVKK BoardLocalization concernsI
AZEAzerbaijanEurasiaLimitedLaw 2010ConsentAccessWeakSomeNoneStateStableI
KAZKazakhstanEurasiaLimitedLaw 2013ConsentAccessWeakSomeNoneState agencyLocalizationI
UZBUzbekistanEurasiaLimitedLaw 2019 (localization)ConsentAccessWeakSomeNoneStateLocalizationI
TKMTurkmenistanEurasiaMinimalNominal (2017)NoneNoneNoneNoneNoneNoneStableI
RUSRussiaEurasiaSubstantial152-FZConsent (opt-in)Access · deleteLimited rulesSpecial-catMandatory (Roskomnadzor)Roskomnadzor · turnover fines (state-run)2024 fine hikesI
ISRIsraelMiddle EastSubstantialPPLConsentAccess · correctLimited rulesSpecial-catMandatoryPPAAdequacy22024 amendmentP·I
JORJordanMiddle EastModeratePDP Law 2023ConsentAccess · correctLimited rulesSpecial-catMandatoryNew (2023)New 2023 lawI
LBNLebanonMiddle EastLimitedLaw 81/2018ConsentAccessWeakSomeNoneWeakWeak enforcementI
MARMoroccoAfricaModerateLaw 09-08ConsentAccess · rectifyLimited rulesSpecial-catEmergingCNDPStableI
TUNTunisiaAfricaLimitedLaw 2004 (reform pending)ConsentAccessWeakSomeNoneINPDPReform pendingI
EGYEgyptAfricaLimitedDP Law 2020 (regs pending)ConsentAccessWeakSomeMandatoryAuthority pendingRegs pendingI
AREUAEMiddle EastModeratePDPL 2021 + DIFC/ADGMConsentAccess · erase · portLimited rulesSpecial-catMandatoryUAE Data OfficeIn forceI
SAUSaudi ArabiaMiddle EastModeratePDPL 2023ConsentAccess · delete · portLimited rulesSpecial-catMandatory (72h)SDAIAIn force 2024I
QATQatarMiddle EastModeratePDPPL 2016ConsentAccess · correctLimited rulesSpecial-catMandatoryNDPOFirst GCC lawI
BHRBahrainMiddle EastModeratePDPL 2018ConsentAccess · correctLimited rulesSpecial-catMandatoryPDP AuthorityStableI
OMNOmanMiddle EastModeratePDPL 2022ConsentAccess · correctLimited rulesSpecial-catMandatoryMTCITIn force 2023I
KWTKuwaitMiddle EastLimitedCITRA reg (2021)ConsentAccessWeakNoneNoneCITRASectoral onlyI
IRQIraqMiddle EastMinimalNo comprehensive lawNoneNoneNoneNoneNoneNoneStableI
IRNIranMiddle EastMinimalNo comprehensive lawNoneNoneNoneNoneNoneNoneDraft billI
GHAGhanaAfricaModerateDPA 2012ConsentAccess · correctLimited rulesSpecial-catEmergingDP CommissionStableI
KENKenyaAfricaSubstantialDPA 2019Opt-inAccess · erase · portConsentSpecial-cat72hODPC · activeActive regulatorI
NGANigeriaAfricaSubstantialNDPA 2023ConsentAccess · eraseLimited rulesSpecial-cat72hNDPCNDPA 2023I
SENSenegalAfricaModerateLaw 2008ConsentAccess · rectifyWeakSpecial-catNoneCDPStableI
ZMBZambiaAfricaLimitedDP Act 2021ConsentAccess · correctWeakSpecial-catMandatoryNew (2021)New 2021 lawI
ZWEZimbabweAfricaLimitedCyber & DP Act 2021ConsentAccessWeakSomeMandatoryPOTRAZStableI
UGAUgandaAfricaModerateDPP Act 2019ConsentAccess · correctWeakSpecial-catMandatoryPDPOStableI
BWABotswanaAfricaModerateDP Act 2018ConsentAccess · correctWeakSpecial-catEmergingInfo & DP CommissionIn force 2021I
NAMNamibiaAfricaWeakBill pendingNoneNoneNoneNoneNoneNoneBill pendingI
SGPSingaporeAsia–PacificSubstantialPDPA 2012Opt-in (consent)Access · correct · portDo-Not-Call + consentSomeMandatory (2021)PDPC · active finesActive enforcerI
MYSMalaysiaAsia–PacificSubstantialPDPA 2010 (2024 amd)ConsentAccess · correctLimited rulesSpecial-catMandatory (2024)PDP Commissioner2024 amendmentsI
PHLPhilippinesAsia–PacificSubstantialDPA 2012ConsentAccess · erase · portConsentSpecial-cat72h (NPC)NPC · activeActive regulatorI
IDNIndonesiaAsia–PacificModeratePDP Law 2022ConsentAccess · erase · portLimited rulesSpecial-cat72hAgency (forming)In force 2024I
THAThailandAsia–PacificSubstantialPDPA 2019Opt-in (consent)Access · erase · portConsentSpecial-cat72hPDPCIn force 2022I
VNMVietnamAsia–PacificSubstantialPDPL 2025Opt-in (explicit)Access · deleteSale bannedSpecial-catMandatoryMPS · up to 5% (state-run)In force Jan 2026I
LKASri LankaAsia–PacificModeratePDPA 2022ConsentAccess · eraseLimited rulesSpecial-catMandatoryDPA (new)New lawI
NPLNepalAsia–PacificLimitedPrivacy Act 2018ConsentAccessWeakSomeNoneWeakLimitedI
KHMCambodiaAsia–PacificWeakDraft lawNoneNoneNoneNoneNoneNoneDraft lawI
MNGMongoliaAsia–PacificModeratePDP Law 2021ConsentAccess · correctLimited rulesSpecial-catMandatoryNew (2021)New 2021 lawI
PAKPakistanAsia–PacificWeakDraft bill (pending)NoneNoneNoneNoneNoneNoneBill pendingI
MMRMyanmarAsia–PacificMinimalNo DP lawNoneNoneNoneNoneNoneNoneJunta ruleI
PRKNorth KoreaAsia–PacificMinimalNo lawNoneNoneNoneNoneNoneNoneNo open internetI

No countries in that tier.

Filled. Strong protection — a right that binds companies, present and enforceable. Half. Present but qualified — opt-out rather than opt-in, partial, or weakly enforced. Open ring. Absent or adverse — no such right, or a rule that favours the company. Dashed. Not located. Grey (any shape). Estimated from the tracker, with no per-country document — shown without a source number.

Reading the columns. Comprehensive law is whether an omnibus statute covers the private sector, or only a sectoral patchwork does. Consent model is the default: opt-in with a lawful basis is more protective than opt-out. Access & deletion is what you can demand of a company — to see, correct, erase, and port your data. Sale & targeted ads is whether selling data or behavioural profiling needs your consent or an opt-out. Sensitive & children is the extra protection for health, biometric, and children’s data. Breach notice is whether a company must tell you and the regulator when your data leaks. Enforcement & penalty is the part that makes the rest real: an independent regulator and a fine large enough to matter. EU adequacy sits here because it is the external verdict on a country’s commercial regime — though Schrems II shows it also weighs state access, so it is not a pure consumer measure. Basis tags each row: P primary-source-driven, P·I mixed, I estimated from the tracker.Checked July 18, 2026 — verify current details before relying on this. General information, not legal advice.

Sources & notes (companies)

Each number matches a superscript in the table above and points to the primary instrument or regulator behind a documented cell. Cells without a number are estimated from the DLA Piper tracker (source 14) and shown in grey. Checked July 18, 2026.

  1. European Union — General Data Protection Regulation (Regulation (EU) 2016/679) — private-sector duties, the individual rights of access, erasure and portability, 72-hour breach notification, and fines up to 4% of global turnover, enforced by an independent authority. eur-lex.europa.eu
  2. European Commission — Adequacy decisions — the external verdict on a country’s data-protection regime; note that Schrems II turned on state access, so adequacy is not a purely commercial measure. commission.europa.eu
  3. United States — California Consumer Privacy Act / CPRA — rights to know, delete, and opt out of the sale or sharing of personal data, enforced by the California Privacy Protection Agency. There is no comprehensive federal statute: a sectoral patchwork (HIPAA, GLBA, COPPA, FCRA) plus a growing set of state laws. oag.ca.gov
  4. China — Personal Information Protection Law (PIPL), effective 1 November 2021 — separate opt-in consent, data minimisation, deletion and portability rights, strict facial-recognition rules, and fines up to 5% of turnover; enforced by the state Cyberspace Administration, not an independent regulator, and subject to broad state carve-outs. dlapiperdataprotection.com
  5. Brazil / European Commission — LGPD, enforced by the ANPD, and the EU–Brazil mutual adequacy decisions of January 2026. ec.europa.eu
  6. Japan — Act on the Protection of Personal Information (APPI), enforced by the independent Personal Information Protection Commission; the first post-GDPR adequacy country. ppc.go.jp
  7. South Korea — Personal Information Protection Act (PIPA). The Personal Information Protection Commission (independent since 2020) has fined Google and Meta tens of millions of dollars; Korea holds EU adequacy. pipc.go.kr
  8. United Kingdom — UK GDPR as amended by the Data (Use and Access) Act 2025 (Royal Assent 19 June 2025) — it keeps the comprehensive framework and EU adequacy while easing some rules (recognised legitimate interests, automated decisions) and adding children’s-protection duties and a right to complain to controllers; enforced by the ICO. legislation.gov.uk
  9. India — Digital Personal Data Protection Act 2023 — consent-based with parental consent for children, but not yet in force, with broad government exemptions and a non-independent Data Protection Board. dlapiperdataprotection.com
  10. South Africa — Protection of Personal Information Act (POPIA), enforced by the Information Regulator; mandatory breach notification and consent-based direct marketing. inforegulator.org.za
  11. Switzerland — Revised Federal Act on Data Protection (in force 1 September 2023), GDPR-aligned, enforced by the FDPIC; Switzerland holds EU adequacy. edoeb.admin.ch
  12. Canada — Personal Information Protection and Electronic Documents Act (PIPEDA), enforced by the Office of the Privacy Commissioner (limited fining power; the Bill C-27 reform lapsed); EU adequacy for commercial data. priv.gc.ca
  13. Australia — Privacy Act 1988 (Australian Privacy Principles) and the Notifiable Data Breaches scheme, enforced by the OAIC; the Privacy and Other Legislation Amendment Act 2024 began a phased strengthening. oaic.gov.au
  14. DLA Piper — Data Protection Laws of the World — the cross-country tracker behind the estimated (Basis “I”) rows and tier placements; the commercial-privacy analog to the internet-freedom index used in the first table. dlapiperdataprotection.com

On method. Tiers, not scores, for the same reason as the first table: the top and bottom are robust, the middle turns on how you weigh paper rights against real enforcement. This is a student project for privacy education; it is not an official index and takes no position on any government.

What the pattern shows

Courts, alliances, and the gap between law and operation

The top tier has a common feature, and it isn’t a privacy law on the books — almost every country has one of those. It’s an independent court willing to strike surveillance powers down. The countries in the strongest tier tend to pair a data-protection statute with a constitutional court that has actually voided a retention mandate or an intelligence power, so the protection holds when a government would rather it didn’t. A statute a legislature can quietly amend is worth less than the same words a court will enforce.

Intelligence-sharing membership caps how high an otherwise-strong democracy can sit. A country can have GDPR-grade law and an active regulator and still run bulk-collection powers or cable interception under a national-security carve-out. Where it does, the table places it a tier below what its commercial protections alone would suggest — which is why several wealthy democracies with excellent consumer-privacy regimes land in the middle rather than the top. The companion table above is where that strength reappears: the UK, the United States, and Australia all sit markedly higher against companies than against their own governments.

One reading needs care, and it’s the reason scores were dropped. A repressive law on the books is not the same as a sealed network in operation. Several states with sweeping surveillance statutes still run comparatively open networks in practice — filtering incomplete, VPN use widespread, no permanent isolation actually achieved — while a smaller set operate the control they legislate. The tiers reflect what a person can actually do, so a legally repressive but operationally leaky regime can sit above a fully operational one. The Trend column carries the direction of travel, which is often where the real story is.

And the honest limit: about a fifth of the rows are documented cell-by-cell; the rest are estimates, and roughly a quarter of all countries fall outside the index this leans on entirely. The Basis tag and the grey markers are there so you can see exactly which is which — the same discipline as our campus transparency table, where an unanswered question is marked, not guessed.

Sources & notes

Each number matches a superscript in the table and points to the primary instrument behind a documented cell. Cells without a number are either a finding of absence or an estimate from the index in source 12 — there’s no single document to link. The estimated rows (Basis I) rest chiefly on that index plus EU-adequacy status and public data-protection-law trackers; they carry no per-country primary source, and roughly a quarter of the list sits outside the index’s 72 countries on the thinnest basis of all. Checked July 11, 2026.

  1. European Union — General Data Protection Regulation (Regulation (EU) 2016/679) — the statutory data-protection framework, and the requirement of an independent supervisory authority, binding in every member state. eur-lex.europa.eu
  2. Court of Justice of the EU — Digital Rights Ireland (2014) struck the blanket Data Retention Directive; La Quadrature du Net (2020) held that general, indiscriminate retention is unlawful save under narrow conditions — the case-law behind the “court-struck” retention cells across the EU. curia.europa.eu (PDF)
  3. European Commission — Adequacy decisions — the official list of non-EU jurisdictions recognised as providing adequate data protection (Japan, South Korea, Argentina, Uruguay, Canada (commercial), the UK, and others). commission.europa.eu
  4. Germany · Federal Constitutional Court — Judgment of 1 October 2024 (Press Release 83/2024): storage powers under §18(1) no.2 and contact-person surveillance under §45(1) no.4 of the BKA Act held incompatible with the right to informational self-determination, effective until 31 July 2025. bundesverfassungsgericht.de
  5. Germany · Federal Constitutional Court — Order of 8 October 2024: strategic cyber-surveillance of international telecommunications by the Federal Intelligence Service (BND) held unconstitutional in part. bundesverfassungsgericht.de
  6. Switzerland — Federal Constitution Art. 13 and the Federal Act on Data Protection (2023). The 2025 revision of the OSCPT/VÜPF surveillance ordinance would add mandatory identification, six-month retention, and — under Art. 50a — a duty to remove provider-applied encryption; Proton has said it would relocate infrastructure in response. swissinfo.ch
  7. United Kingdom — Investigatory Powers Act 2016 — bulk powers, 12-month Internet Connection Record retention, and secret Technical Capability Notices (the mechanism behind the Apple encryption demand). legislation.gov.uk
  8. United Kingdom — Online Safety Act 2023 — “highly effective age assurance” duties, in force from 25 July 2025. legislation.gov.uk
  9. United States · Congress — Congressional Research Service R48592 on FISA Section 702 and the 2024 RISAA: reauthorised 20 April 2024, broadened the “electronic communication service provider” definition, sunsets 20 April 2026. The US has no comprehensive federal privacy statute. congress.gov
  10. Australia — Telecommunications (Assistance and Access) Act 2018 (decryption-assistance regime) and the mandatory metadata-retention scheme under the Telecommunications (Interception and Access) Act. legislation.gov.au
  11. Russia · documentation — Human Rights Watch, Disrupted, Throttled, and Blocked (2025) — documents SORM, the 2019 “sovereign internet” law and Yarovaya retention, and that filtering/isolation remain incomplete in practice (the basis for the operational-vs-legal reading). hrw.org
  12. Freedom House — Freedom on the Net 2025 — the cross-country internet-freedom index behind the estimated (Basis “I”) rows and the tier placements; it also documents China and Myanmar as the worst environments and the UK’s 2025 demands to Apple. It assesses 72 countries, so the roughly 28 outside it rest on the thinnest basis of all. freedomhouse.org
  13. Brazil / European Commission — Brazil’s LGPD and the EU–Brazil mutual adequacy decisions of 26–27 January 2026 (European Commission Implementing Decision (EU) 2026/179; ANPD Resolution No. 32/2026). ec.europa.eu
  14. Japan — Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, amended 2020), enforced by the independent Personal Information Protection Commission; Japan was the first country to receive an EU adequacy decision after the GDPR. ppc.go.jp
  15. South Korea — Personal Information Protection Act (PIPA, 2011). The 2020 amendment made the Personal Information Protection Commission an independent regulator, which has fined Google and Meta tens of millions of dollars; privacy is a constitutional right and Korea holds EU adequacy. pipc.go.kr
  16. India · Supreme Court — K. S. Puttaswamy v. Union of India (2017) held privacy to be a fundamental right under Article 21; the Digital Personal Data Protection Act 2023 grants broad state exemptions and a non-independent board, and the Aadhaar programme is a mass biometric-identity system. globalfreedomofexpression.columbia.edu
  17. China — Personal Information Protection Law (PIPL), effective 1 November 2021 — a comprehensive statute that binds companies (including rules on facial-recognition use) but does not constrain state surveillance. dlapiperdataprotection.com
  18. South Africa · Constitutional Court — amaBhungane v Minister of Justice [2021] ZACC 3 (4 February 2021) held RICA’s bulk interception unlawful and the Act unconstitutional in five respects; POPIA (Act 4 of 2013) and Constitution §14 protect privacy. saflii.org
  19. European Union — Regulation (EU) 2021/1232, the temporary ePrivacy derogation permitting voluntary provider scanning of non-encrypted communications for known CSAM. Lapsed 3 April 2026; reinstated 9 July 2026 to run until 3 April 2028; it does not reach end-to-end-encrypted messages. eur-lex.europa.eu
  20. European Parliament — Press release on the 9 July 2026 second-reading vote (“Combating child sexual abuse: support for a more limited ePrivacy derogation”): the motion to reject the Council position drew 314 votes to 276, short of the 361-vote absolute majority needed to block it, so the derogation stands. The permanent Child Sexual Abuse Regulation, COM(2022) 209, remains in trilogue. europarl.europa.eu
  21. United States — 18 U.S.C. § 2258A. Providers are not required to search for CSAM but may scan voluntarily (hash-matching on non-encrypted surfaces such as Gmail, Messenger, and cloud storage) and must report anything found to NCMEC’s CyberTipline. law.cornell.edu
  22. United Kingdom — Online Safety Act 2023, s.121 (the former cl.122 “spy clause”): Ofcom may issue a Technology Notice requiring a provider to use “accredited technology” to scan for CSEA or terrorism content, including on end-to-end-encrypted services. The power is not yet exercised — the government has said it will not be used until “technically feasible,” and no technologies had been accredited as of mid-2026. ofcom.org.uk

On method. Tiers replace the exact scores from the underlying research, because a five-tier range is far more defensible than a precise 1-to-100 ordering — the top and bottom are robust, the middle is sensitive to how you weigh state surveillance against commercial protection. This is a student project for privacy education; it is not an official index, and it takes no position on any government.

Get involved

It’s free, open to everyone at Pitt, and joining takes about a minute.

No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.