Privacy worldwide
100 countries, sorted by the privacy their laws provide.
Grouped into seven tiers, from constitutional limits on the state down to pervasive surveillance. Not a ranking — a tier is a range, and the order within one carries no meaning. Two tables, two directions — protection from the state, and protection from companies — and a country can rank high on one while low on the other.
How to read this. Every country sits in one of seven tiers by how much privacy its law provides in practice — not by how much surveillance it runs. The table has two kinds of rows. Documented rows trace cell‑by‑cell to a primary instrument — a constitution, a statute, a court ruling, an adequacy decision — and those cells carry a source number. The rest are estimates, placed from a cross‑country internet‑freedom index with no per‑country privacy document behind them; they are shown in grey, without a number, on purpose. Scores were dropped deliberately: tiers are far more defensible than any exact rank. Policies change — verify current details before relying on this. General information, not legal advice.
Checked July 11, 2026How the tiers work
Seven tiers, strongest to weakest
The tiers describe the level of privacy protection a person effectively has, end to end. The meter shows the tier at a glance — more filled bars mean more protection. The columns carry the mechanism — whether the protection is constitutional or merely statutory, whether retention is mandatory, whether encryption can be compelled.
- Comprehensive protections. A data-protection statute plus a constitutional court that has actually struck surveillance powers down — protection that survives a change of government.
- Strong protections. Robust statutory rights and an active regulator; any bulk-collection or retention power is limited, contested, or under judicial pressure.
- Substantial protections. Solid data-protection law and enforcement, but with a standing retention mandate or an intelligence power that isn’t fully checked.
- Moderate protections. Real law on the books, weaker enforcement, and state-access powers that cut against it.
- Limited protections. Sweeping retention or bulk powers, or a compelled-assistance regime, outweigh the statutory protections that exist.
- Weak protections. Broad state access and thin oversight; the law itself does little to constrain surveillance.
- Minimal protections. Pervasive state surveillance, localization or interception mandates, and little or no independent oversight.
The tags under a country
Five, Nine, and Fourteen Eyes
A handful of countries carry a small slate tag — Fourteen Eyes — beneath their name. These name an intelligence-sharing arrangement that grew out of a postwar signals-intelligence pact, in which the member states share the communications their agencies intercept. It is one club in three rings, not three separate ones: each wider ring contains the one inside it.
- 5Five Eyes
The original core — the United States, the United Kingdom, Canada, Australia, and New Zealand.
- 9Nine Eyes
The Five, plus Denmark, France, the Netherlands, and Norway.
- 14Fourteen Eyes
The Nine, plus Germany, Belgium, Italy, Spain, and Sweden.
So the rings nest. Whatever the innermost Five share reaches the Nine and the Fourteen as well — the wider the ring, the more governments see the same intercept. A country’s tag marks the ring it enters at: the smallest circle that already includes it, which is why a partner such as France reads Nine Eyes rather than Five.
That is why the tag belongs on a privacy page. A member can receive what its partners collect, so communications a country’s own courts might forbid it to gather can still reach its agencies through an ally — which is what caps how high an otherwise-strong democracy can sit in the tables below. The fuller version of that argument is at the foot of the page.
Membership is documented through declassified records of the UKUSA arrangement and reporting on leaked intelligence files, rather than any single public statute; it is shown here as background, not as a rated cell. Checked July 11, 2026.
The first table
100 countries, rated against the state
Filter by tier, or sort A–Z. Each marker reads on a single scale — the more filled the shape, the more protection — and works in greyscale. Grey markers are estimates; coloured markers with a number are documented.
Protection from the state100 countries · sort by tier or A–Z
| Country | Protection from the state | Legal basis | Data retention | Message scanning | Encryption | Biometric | Enforcement | EU adequacy | Trend | Basis |
|---|---|---|---|---|---|---|---|---|---|---|
| ESTEstoniaEurope | Comprehensive | Constitutional1 | Targeted2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | P·I |
| ISLIcelandEurope | Comprehensive | GDPR (EEA)1 | None | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EEA | →Freest (FOTN)12 | I |
| DEUGermanyEurope Fourteen Eyes | Comprehensive | Constitutional1,4,5 | None in force2,4 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Courts active4,5 | P |
| AUTAustriaEurope | Comprehensive | GDPR · DSG1 | Court-struck2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | P |
| PRTPortugalEurope | Comprehensive | Constitutional1 | Court-struck ’222 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | ↑Post-strike | P |
| SVNSloveniaEurope | Comprehensive | GDPR · ZVOP-21 | Court-struck2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | I |
| FINFinlandEurope | Comprehensive | Constitutional1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | P·I |
| IRLIrelandEurope | Comprehensive | GDPR1 | Targeted (post-DRI)2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Weak enforcement | EU | →Stable | P |
| CRICosta RicaAmericas | Comprehensive | Constitutional | Targeted | No scanning regime | No compulsion | Restricted | Agency | — | →Stable | I |
| CHLChileAmericas | Comprehensive | Constitutional | Targeted | No scanning regime | No compulsion | Restricted | New agency | — | ↑New GDPR-style law | P·I |
| JPNJapanAsia–Pacific | Comprehensive | APPI14 | Targeted | No scanning regime | No compulsion | Restricted | PPC14 | Adequacy3 | →Stable | P·I |
| URYUruguayAmericas | Comprehensive | Ley 18.331 | Targeted | No scanning regime | No compulsion | Restricted | URCDP | Adequacy3 | →Stable | I |
| LUXLuxembourgEurope | Comprehensive | GDPR1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | CNPD1 | EU | →Stable | I |
| CHESwitzerlandEurope | Comprehensive | Const · FADP6 | Mandatory ~6mo6 | No scanning regime | Decryption (proposed)6 | Not located | FDPIC6 | Adequacy3 | ↓OSCPT revision; Proton exit6 | P |
| CZECzechiaEurope | Strong | GDPR1 | Court-struck2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | P |
| NLDNetherlandsEurope Nine Eyes | Strong | GDPR · UAVG1 | Struck ’152 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →9 Eyes | P |
| NORNorwayEurope Nine Eyes | Strong | GDPR (EEA)1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EEA | →9 Eyes | P·I |
| TWNTaiwanAsia–Pacific | Strong | PDPA | Targeted | No scanning regime | No compulsion | Restricted | New PDPC | — | ↑New DPA (2025) | P·I |
| BELBelgiumEurope Fourteen Eyes | Strong | GDPR1 | Re-legislated | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →14 Eyes | P |
| ESPSpainEurope Fourteen Eyes | Strong | LOPDGDD1 | Mandatory (contested) | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | AEPD · active1 | EU | →14 Eyes | P |
| DNKDenmarkEurope Nine Eyes | Strong | GDPR1 | Session logging | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | ↓Retention revival | P·I |
| NZLNew ZealandAsia–Pacific Five Eyes | Strong | Privacy Act 2020 | Targeted | No scanning regime | Assistance regime | Restricted | Commissioner | — | →5 Eyes | P·I |
| FRAFranceEurope Nine Eyes | Strong | GDPR1 | Mandatory (nat-sec) | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | CNIL · active1 | EU | ↓LQDN II reopened retention2 | P |
| LTULithuaniaEurope | Strong | GDPR1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | VDAI1 | EU | →Stable | I |
| LVALatviaEurope | Strong | GDPR1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | DVI1 | EU | →Stable | I |
| ARGArgentinaAmericas | Strong | Ley 25.326 | Targeted | No scanning regime | No compulsion | Restricted | AAIP | Adequacy3 | →Stable | P·I |
| ITAItalyEurope Fourteen Eyes | Strong | GDPR1 | Up to 72mo | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Garante · active1 | EU | →14 Eyes | P |
| SWESwedenEurope Fourteen Eyes | Strong | GDPR1 | Mandatory · FRA | Voluntary (CC 1.0)19,20 | Backdoor push ’25 | Restricted (GDPR)1 | Independent1 | EU | ↓FRA + encryption bill | P |
| POLPolandEurope | Substantial | GDPR1 | Mandatory 12mo | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Broad police access | EU | ↓Oversight gaps | P·I |
| CANCanadaAmericas Five Eyes | Substantial | PIPEDA | Targeted | No scanning regime | Lawful-access bills | Restricted | OPC | Adequacy3 | ↓Lawful-access bills | P·I |
| GRCGreeceEurope | Substantial | GDPR1 | Mandatory | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Predator scandal | EU | ↓Predator affair | P·I |
| HRVCroatiaEurope | Substantial | GDPR1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | AZOP1 | EU | →Stable | I |
| CYPCyprusEurope | Substantial | GDPR1 | Contested | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Commissioner1 | EU | →Stable | I |
| SVKSlovakiaEurope | Substantial | GDPR1 | Court-struck2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | I |
| BRABrazilAmericas | Substantial | LGPD13 | Marco Civil | No scanning regime | No compulsion | LGPD-restricted | ANPD13 | Adequacy ’2613,3 | ↑EU adequacy (2026)13 | P·I |
| MLTMaltaEurope | Substantial | GDPR1 | Targeted | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | IDPC1 | EU | →Stable | I |
| ROURomaniaEurope | Substantial | GDPR1 | Repeatedly struck2 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | P·I |
| BGRBulgariaEurope | Substantial | GDPR1 | Struck ’152 | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Independent1 | EU | →Stable | I |
| ZAFSouth AfricaAfrica | Substantial | POPIA · Const §1418 | RICA (amaBhungane)18 | No scanning regime | No compulsion | POPIA-restricted | Regulator | — | ↑Post-amaBhungane | P |
| KORSouth KoreaAsia–Pacific | Substantial | PIPA15 | Mandatory | No scanning regime | Assistance regime | Restricted | PIPC · active15 | Adequacy3 | →Content controls | P·I |
| HUNHungaryEurope | Substantial | GDPR1 | Mandatory | Voluntary (CC 1.0)19,20 | No compulsion | Restricted (GDPR)1 | Pegasus operator | EU | ↓Illiberal drift | P·I |
| GHAGhanaAfrica | Substantial | DPA 2012 | Targeted | No scanning regime | No compulsion | Not located | Commission | — | →Stable | I |
| COLColombiaAmericas | Moderate | Ley 1581 | Targeted | No scanning regime | No compulsion | Not located | SIC | — | →Stable | I |
| MEXMexicoAmericas | Moderate | LFPDPPP | Mandatory | No scanning regime | No compulsion | Not located | INAI abolished ’25 | — | ↓INAI dissolution | P·I |
| ECUEcuadorAmericas | Moderate | LOPDP 2021 | Targeted | No scanning regime | No compulsion | Not located | Authority | — | ↑New law | I |
| ARMArmeniaEurasia | Moderate | Law 2015 | Targeted | No scanning regime | No compulsion | Not located | Agency | — | →Stable | I |
| SRBSerbiaEurope | Moderate | ZZPL | Mandatory | No scanning regime | No compulsion | Safe City CCTV | Commissioner | — | ↓Smart-city CCTV | I |
| MDAMoldovaEurope | Moderate | Law 133 | Targeted | No scanning regime | No compulsion | Not located | Centre | — | ↑EU-alignment | I |
| UKRUkraineEurope | Moderate | PDP law (wartime) | Wartime powers | No scanning regime | No compulsion | Not located | Ombudsman | — | →Wartime | I |
| MNGMongoliaAsia–Pacific | Moderate | Law 2021 | Targeted | No scanning regime | No compulsion | Not located | Authority | — | →Stable | I |
| USAUnited StatesAmericas Five Eyes | Moderate | No federal statute9 | Provider-retained | Voluntary (providers)21 | No general mandate | State patchwork | No federal DPA | DPF3 | ↓§702 / RISAA; broker buys9 | P |
| GEOGeorgiaEurasia | Moderate | PDP law | Mandatory | No scanning regime | No compulsion | Not located | Foreign-agent law | — | ↓↓Foreign-influence law | P·I |
| ISRIsraelMiddle East | Moderate | PPL | Mandatory | No scanning regime | Assistance regime | Deployed | PPA | — | ↓Surveillance exports | P·I |
| MYSMalaysiaAsia–Pacific | Moderate | PDPA (2024 amd) | Mandatory | No scanning regime | Assistance regime | Emerging | Commissioner | — | →Content controls | I |
| PHLPhilippinesAsia–Pacific | Moderate | DPA 2012 | Targeted | No scanning regime | No compulsion | Emerging | NPC | — | ↓SIM registration | I |
| NAMNamibiaAfrica | Moderate | Bill pending | Targeted | No scanning regime | No compulsion | Not located | None yet | — | →Stable | I |
| BWABotswanaAfrica | Limited | DPA 2018 | Targeted | No scanning regime | No compulsion | Not located | Commission | — | →Stable | I |
| GBRUnited KingdomEurope Five Eyes | Limited | DUAA 2025 | 12mo ICRs7 | Scanning power (OSA)22 | TCN power7 | Live FR | ICO | Adequacy3 | ↓↓IPA · OSA · Apple order7,8,12 | P |
| AUSAustraliaAsia–Pacific Five Eyes | Limited | Privacy Act 1988 | Mandatory 24mo10 | No scanning regime | Decryption (TOLA)10 | Emerging | OAIC | — | ↓TOLA, retention10 | P·I |
| TUNTunisiaAfrica | Limited | Law 2004-63 | Targeted | No scanning regime | No compulsion | Not located | INPDP | — | →Stable | I |
| SENSenegalAfrica | Limited | Law 2008-12 | Targeted | No scanning regime | No compulsion | Not located | CDP | — | →Stable | I |
| KENKenyaAfrica | Limited | DPA 2019 | Targeted | No scanning regime | No compulsion | Emerging | ODPC | — | ↓Protest shutdown ’24 | I |
| NGANigeriaAfrica | Limited | DPA 2023 | Targeted | No scanning regime | No compulsion | Emerging | NDPC | — | ↑New law | I |
| ZMBZambiaAfrica | Limited | DPA 2021 | Targeted | No scanning regime | No compulsion | Not located | Authority | — | →Stable | I |
| IDNIndonesiaAsia–Pacific | Limited | PDP 2022 | Localization | No scanning regime | Assistance regime | Emerging | Authority | — | ↓Localization | I |
| LKASri LankaAsia–Pacific | Limited | PDPA 2022 | Targeted | No scanning regime | No compulsion | Not located | Authority | — | ↑New law | I |
| JORJordanMiddle East | Limited | PDP 2023 | Mandatory | No scanning regime | Assistance regime | Not located | Authority | — | ↑New law | I |
| LBNLebanonMiddle East | Limited | Law 81/2018 | Targeted | No scanning regime | No compulsion | Not located | Weak | — | →Stable | I |
| INDIndiaAsia–Pacific | Limited | Puttaswamy · DPDP16 | Localization (emerging) | No scanning regime | Decryption (IT §69) | Aadhaar16 | Non-independent board16 | — | ↓DPDP state exemptions | P |
| MARMoroccoAfrica | Limited | Law 09-08 | Mandatory | No scanning regime | Assistance regime | Not located | CNDP | — | ↓Pegasus | I |
| SGPSingaporeAsia–Pacific | Weak | PDPA 2012 | Mandatory | Broad state access | Assistance regime | National biometric | PDPC | — | →High state access | P·I |
| NPLNepalAsia–Pacific | Weak | Privacy Act 2018 | Targeted | Broad state access | No compulsion | Not located | Not located | — | →Stable | I |
| PERPeruAmericas | Weak | Ley 29733 | Mandatory | Broad state access | No compulsion | Not located | ANPD | — | →Stable | I |
| KWTKuwaitMiddle East | Weak | CITRA regs | Mandatory | Broad state access | Assistance regime | Emerging | CITRA | — | →Broad access | I |
| QATQatarMiddle East | Weak | Law 13/2016 | Mandatory | Broad state access | Assistance regime | Biometric CCTV | Authority | — | →Pervasive monitoring | I |
| OMNOmanMiddle East | Weak | PDPL 2022 | Mandatory | Broad state access | Assistance regime | Emerging | Authority | — | →Broad exemptions | I |
| KAZKazakhstanEurasia | Weak | Law 2013 | SORM model | Broad state access | HTTPS-interception | TargetEYE FR | Authority | — | ↓Buildout (incomplete) | P·I |
| UGAUgandaAfrica | Weak | DPA 2019 | Mandatory | Broad state access | Assistance regime | Huawei CCTV | Authority | — | ↓Pegasus / CCTV | I |
| ZWEZimbabweAfrica | Weak | DPA 2021 | Mandatory | Broad state access | Assistance regime | FR pilot | Authority | — | →Stable | I |
| THAThailandAsia–Pacific | Weak | PDPA 2019 | Mandatory | Broad state access | Assistance regime | Deployed | Committee | — | ↓Content control | I |
| KHMCambodiaAsia–Pacific | Weak | Sub-decree (NIG) | NIG gateway | Broad state access | Assistance regime | Deployed | None | — | ↓NIG buildout | I |
| AZEAzerbaijanEurasia | Weak | Pervasive monitoring | Mandatory | Broad state access | Assistance regime | Not located | None | — | ↓Pegasus | I |
| BHRBahrainMiddle East | Weak | PDPL 2018 | Mandatory | Broad state access | Assistance regime | Biometric CCTV | Authority | — | ↓Spyware | I |
| IRQIraqMiddle East | Weak | No comprehensive law | Mandatory | Broad state access | Assistance regime | Not located | None | — | →Shutdowns | I |
| PAKPakistanAsia–Pacific | Minimal | PECA 2016 | Web Monitoring System | Broad state access | De facto compelled | Deployed | None | — | ↓↓Firewall buildout | I |
| TURTurkeyEurasia | Minimal | KVKK | Mandatory | Broad state access | Assistance regime | Deployed | KVKK board | — | ↓Content control | P·I |
| EGYEgyptAfrica | Minimal | DP Law 2020 | Mandatory | Broad state access | Assistance regime | Deployed | Regs pending | — | ↓Mass surveillance | I |
| VENVenezuelaAmericas | Minimal | No independent DPA | Mandatory | Broad state access | Assistance regime | Deployed | None | — | ↓↓CANTV monitoring | I |
| AREUAEMiddle East | Minimal | PDPL 2021 (regs unissued) | Mandatory | Broad state access | De facto compelled | Biometric CCTV | Authority | — | ↓Spyware, biometrics | P·I |
| SAUSaudi ArabiaMiddle East | Minimal | PDPL (state-exempt) | Localization | Broad state access | De facto compelled | Biometric CCTV | SDAIA | — | ↓State-exempt enforcement | P·I |
| UZBUzbekistanEurasia | Minimal | Law 2019 (localization) | SORM model | Broad state access | De facto compelled | State biometric | Authority | — | ↓Buildout (incomplete) | P·I |
| VNMVietnamAsia–Pacific | Minimal | PDPD 2023 | Localization | Broad state access | De facto compelled | Deployed | Authority | — | ↓Localization, control | P·I |
| CUBCubaAmericas | Minimal | Decree 370 | Mandatory | Broad state access | De facto compelled | Not located | State ISP monopoly | — | ↓ETECSA monopoly | I |
| BLRBelarusEurope | Minimal | Nominal | SORM · DPI | Broad state access | De facto compelled | Deployed | None | — | ↓↓Near-total in crises | P·I |
| RUSRussiaEurasia | Minimal | Nominal | SORM-3 · Yarovaya11 | State interception11 | Key disclosure11 | FR network | No independent DPA | — | ↓↓Sovereign-internet buildout (incomplete)11 | P |
| MMRMyanmarAsia–Pacific | Minimal | Junta rule | Mandatory | Broad state access | De facto compelled | Junta biometric | None | — | ↓↓Junta control (not sealed)12 | I |
| IRNIranMiddle East | Minimal | Nominal | Mandatory | Broad state access | De facto compelled | Deployed | None | — | ↓↓NIN advanced; full shutdowns12 | P·I |
| TKMTurkmenistanEurasia | Minimal | Nominal (2017) | Total | Broad state access | De facto compelled | State control | None | — | ↓Near-total control12 | I |
| CHNChinaAsia–Pacific | Minimal | PIPL (firms)17 | Real-name · comprehensive12 | State interception12 | Backdoor / compelled12 | Skynet · FR12 | PIPL on firms | — | →Great Firewall operational12 | P |
| PRKNorth KoreaAsia–Pacific | Minimal | No open internet | Total | Broad state access | Intranet only | Total control | None | — | →Kwangmyong only12 | I |
No countries in that tier.
Reading the columns. Legal basis is whether privacy rests on an enforceable constitutional right, ordinary statute, or little at all. Data retention asks whether communications metadata must be kept — less is more protective. Message scanning is whether the law lets or makes providers inspect the content of private messages without individualized suspicion — a filled marker means no such regime, a half marker means voluntary scanning of non-encrypted surfaces, an open ring means a scanning mandate, client-side scanning, or broad state interception; it is distinct from encryption, which follows. Encryption is whether providers can be compelled to weaken or break it. Biometric is the reach of state facial-recognition and biometric-ID systems — a filled marker means little or none, an open ring means pervasive deployment. How those systems — automated plate readers, face recognition, always-on sensors — actually work is on our cameras & sensors page. Enforcement is whether an independent regulator actually acts. EU adequacy is here because it is the one external, independent verdict on a country’s data-protection regime: the European Commission formally judging it essentially equivalent to the GDPR. It is Euro-centric and many countries never sought it, so a dash is not a demerit — only the positive mark carries weight. Five / Nine / Fourteen Eyes intelligence-sharing appears as a tag under the country name, because it caps how high an otherwise-strong democracy can sit. Basis tags each row: P primary-source-driven, P·I mixed, I estimated from the index. A cell shows a number only where the primary instrument could be linked directly; some documented rows are summarised without a per-cell link.Checked July 11, 2026 — verify current details before relying on this. General information, not legal advice.
The other direction
The same countries, rated against companies
The table above asks how well a country’s law restrains the state. This one asks the opposite: how well it restrains companies — whether you can see what a business holds on you, delete it, refuse the sale of it, and whether a regulator will make that stick. They are different questions, and a country can sit at opposite ends of each.
China is the clearest case. It is in the bottom tier against the state — and near the top against companies, because its Personal Information Protection Law is one of the strictest corporate-data regimes anywhere: separate opt-in consent, deletion and portability rights, hard limits on facial recognition, and fines up to 5% of turnover. The pattern repeats — several authoritarian states bind companies tightly while exempting themselves, and the Five / Nine / Fourteen Eyes democracies, capped in the first table by their intelligence powers, are not capped here, so their commercial-privacy strength shows through. The European Union sits at the top of both.
Same discipline as the first table: documented rows trace to the statute or regulator behind them and carry a source number; estimated rows rest on the DLA Piper cross-country tracker — the commercial-privacy analog to the internet-freedom index used above — and are shown in grey without a number. This is a first tranche: the strongest regimes and the marquee reversals are placed; the weaker-protection countries follow in the next pass. General information, not legal advice.
One company-side practice these columns don’t yet capture: surveillance pricing — being charged a different price based on what a company knows about you. There is little law on it anywhere; the nearest hook is the GDPR’s limit on decisions “based solely on automated processing,” including profiling. We take it apart on the financial privacy page.
- Comprehensive protections. An omnibus data-protection law binding the private sector, opt-in consent, the full set of individual rights — access, deletion, portability — and an independent regulator that levies real, turnover-scaled fines.
- Strong protections. A comprehensive law and an active regulator with most rights intact; penalties are real but lower, the regulator isn’t fully independent, or one axis such as consent or ad-targeting is weaker.
- Substantial protections. Solid law and rights on paper, but enforcement is uneven or under-resourced, or a strengthening reform has stalled.
- Moderate protections. A law exists — often newer, sectoral, or opt-out — with only partial rights or a young, underpowered regulator.
- Limited protections. Coverage is narrow or not yet in force, consent rules are weak, and there is little enforcement against companies.
- Weak protections. Minimal statutory obligations on companies; any regulator is nominal.
- Minimal protections. No meaningful private-sector data-protection law, or none that is enforced.
Protection from companies100 countries · sort by tier or A–Z
| Country | Protection from companies | Comprehensive law | Consent model | Access & deletion | Sale & targeted ads | Sensitive & children | Breach notice | Enforcement & penalty | EU adequacy | Trend | Basis |
|---|---|---|---|---|---|---|---|---|---|---|---|
| ESTEstoniaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| DEUGermanyEurope Fourteen Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| AUTAustriaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| PRTPortugalEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| SVNSloveniaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| FINFinlandEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| IRLIrelandEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPC · backlog | EU | →Stable | P |
| LUXLuxembourgEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| NLDNetherlandsEurope Nine Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| BELBelgiumEurope Fourteen Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| ESPSpainEurope Fourteen Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| DNKDenmarkEurope Nine Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| FRAFranceEurope Nine Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| LTULithuaniaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| LVALatviaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| ITAItalyEurope Fourteen Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| SWESwedenEurope Fourteen Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| CZECzechiaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| POLPolandEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| GRCGreeceEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| HRVCroatiaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| CYPCyprusEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| SVKSlovakiaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| MLTMaltaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| ROURomaniaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| BGRBulgariaEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| HUNHungaryEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EU | →Stable | P |
| ISLIcelandEurope | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EEA | →Stable | P |
| NORNorwayEurope Nine Eyes | Comprehensive | Omnibus (GDPR)1 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat · Art. 8 | 72h to DPA | DPA · up to 4% turnover1 | EEA | →Stable | P |
| CHESwitzerlandEurope | Comprehensive | FADP 202311 | Opt-in | Access · erase · port | Consent required | Special-cat | Mandatory | FDPIC11 | Adequacy2 | →Stable | P |
| KORSouth KoreaAsia–Pacific | Comprehensive | PIPA7 | Opt-in (strict) | Access · erase · port | Consent required | Strict | Mandatory | PIPC · large fines7 | Adequacy2 | →Active enforcer | P |
| BRABrazilAmericas | Comprehensive | LGPD5 | Opt-in · lawful basis | Access · erase · port | Consent required | Special-cat | Mandatory | ANPD5 | Adequacy ’265 | ↑EU adequacy 2026 | P |
| JPNJapanAsia–Pacific | Strong | APPI6 | Opt-out for sharing | Access · erase | Opt-out (sharing) | Special-cat | Mandatory (2022) | PPC6 | Adequacy2 | →Stable | P |
| GBRUnited KingdomEurope Five Eyes | Strong | UK GDPR · DUAA ’258 | Opt-in · lawful basis | Access · erase · port | Consent (PECR) | Children’s code | 72h to ICO | ICO · up to 4% | Adequacy2 | ↓DUAA loosening8 | P |
| ARGArgentinaAmericas | Strong | Ley 25.32614 | Opt-in | Access · rectify · delete | Limited rules | Special-cat | Emerging | AAIP | Adequacy2 | →Reform pending | P·I |
| URYUruguayAmericas | Strong | Ley 18.33114 | Opt-in | Access · delete | Limited rules | Special-cat | Emerging | URCDP | Adequacy2 | →Stable | P·I |
| NZLNew ZealandAsia–Pacific Five Eyes | Strong | Privacy Act 202014 | IPPs (consent) | Access · correct | Limited rules | Emerging | Notifiable (2020) | Commissioner | — | →Stable | P·I |
| TWNTaiwanAsia–Pacific | Strong | PDPA14 | Consent-based | Access · delete | Limited rules | Special-cat | Emerging | New PDPC (2025) | — | ↑New DPA 2025 | P·I |
| CHNChinaAsia–Pacific | Strong | PIPL4 | Opt-in (separate consent) | Access · delete · port | Consent required | Strict (FR limits) | Mandatory | CAC · up to 5% (state-run)4 | — | →Strict on firms | P |
| CANCanadaAmericas Five Eyes | Substantial | PIPEDA12 | Consent-based | Access · correct | Limited rules | Emerging | Mandatory (PIPEDA) | OPC · weak fines12 | Adequacy (comm.)2 | →Reform stalled (C-27) | P·I |
| AUSAustraliaAsia–Pacific Five Eyes | Substantial | Privacy Act 198813 | APPs | Access · correct | Limited rules | Children’s code (2024) | Notifiable (NDB) | OAIC | — | ↑2024 reforms13 | P·I |
| ZAFSouth AfricaAfrica | Substantial | POPIA10 | Consent-based | Access · delete | Marketing opt-in | Special-cat | Mandatory | Info Regulator10 | — | →Stable | P |
| USAUnited StatesAmericas Five Eyes | Moderate | No federal omnibus · state laws3 | Opt-out (state) | Access · delete (state) | Opt-out of sale (CCPA)3 | COPPA (children) | Breach laws (all states) | FTC · state AGs · CPPA3 | DPF2 | →State patchwork growing | P |
| INDIndiaAsia–Pacific | Limited | DPDP 2023 (rules pending)9 | Consent (once in force) | Access · erase (pending) | No opt-out yet | Parental consent | Mandatory (pending) | Non-independent board9 | — | ↑DPDP not yet in force | P |
| CRICosta RicaAmericas | Substantial | Ley 8968 | Opt-in | Access · rectify | Limited rules | Special-cat | Emerging | PRODHAB | — | →Stable | I |
| CHLChileAmericas | Substantial | Ley 21.719 | Opt-in | Access · erase · port | Consent (pending) | Special-cat | Mandatory (’26) | New APDP (’26) | — | ↑In force Dec 2026 | I |
| COLColombiaAmericas | Substantial | Ley 1581 | Opt-in | Access · delete | Registry rules | Special-cat | Mandatory | SIC · active | — | →Active enforcer | I |
| ECUEcuadorAmericas | Moderate | LOPDP 2021 | Opt-in | Access · erase | Limited rules | Special-cat | Mandatory | Superintendencia | — | ↑Young regulator | I |
| MEXMexicoAmericas | Moderate | LFPDPPP | Opt-out (ARCO) | ARCO rights | Limited rules | Special-cat | Mandatory | Exec ministry (non-indep) | — | ↓INAI abolished 2025 | I |
| PERPeruAmericas | Moderate | Ley 29733 | Opt-in | Access · delete | Limited rules | Special-cat | Emerging | APDP | — | →Stable | I |
| VENVenezuelaAmericas | Weak | No comprehensive law | None | Habeas data (const.) | None | None | None | None | — | →Stable | I |
| CUBCubaAmericas | Limited | Decree-Law 2022 | Consent | Access | None | Some | None | State body | — | →Stable | I |
| SRBSerbiaEurope | Substantial | PDP Law 2018 | Opt-in | Access · erase · port | Consent | Special-cat | 72h | Commissioner | — | →GDPR-aligned | I |
| MDAMoldovaEurope | Moderate | PDP Law | Opt-in | Access · rectify | Limited rules | Special-cat | Emerging | NCPDP | — | ↑GDPR alignment | I |
| UKRUkraineEurope | Moderate | Law 2010 (reform pending) | Consent | Access · rectify | Weak | Special-cat | None | Ombudsman | — | ↑GDPR reform | I |
| BLRBelarusEurope | Limited | PDP Law 2021 | Consent | Access | Weak | Some | None | State (NPDP) | — | →State-aligned | I |
| ARMArmeniaEurasia | Moderate | PDP Law 2015 | Opt-in | Access · rectify | Weak | Special-cat | None | Agency | — | →Stable | I |
| GEOGeorgiaEurasia | Substantial | PDP Law 2023 | Opt-in | Access · erase · port | Consent | Special-cat | 72h | PDP Service | — | ↑New 2023 law | I |
| TURTurkeyEurasia | Moderate | KVKK 2016 | Opt-in (explicit) | Access · delete | Limited rules | Special-cat | Mandatory | KVKK Board | — | →Localization concerns | I |
| AZEAzerbaijanEurasia | Limited | Law 2010 | Consent | Access | Weak | Some | None | State | — | →Stable | I |
| KAZKazakhstanEurasia | Limited | Law 2013 | Consent | Access | Weak | Some | None | State agency | — | →Localization | I |
| UZBUzbekistanEurasia | Limited | Law 2019 (localization) | Consent | Access | Weak | Some | None | State | — | →Localization | I |
| TKMTurkmenistanEurasia | Minimal | Nominal (2017) | None | None | None | None | None | None | — | →Stable | I |
| RUSRussiaEurasia | Substantial | 152-FZ | Consent (opt-in) | Access · delete | Limited rules | Special-cat | Mandatory (Roskomnadzor) | Roskomnadzor · turnover fines (state-run) | — | ↑2024 fine hikes | I |
| ISRIsraelMiddle East | Substantial | PPL | Consent | Access · correct | Limited rules | Special-cat | Mandatory | PPA | Adequacy2 | ↑2024 amendment | P·I |
| JORJordanMiddle East | Moderate | PDP Law 2023 | Consent | Access · correct | Limited rules | Special-cat | Mandatory | New (2023) | — | ↑New 2023 law | I |
| LBNLebanonMiddle East | Limited | Law 81/2018 | Consent | Access | Weak | Some | None | Weak | — | →Weak enforcement | I |
| MARMoroccoAfrica | Moderate | Law 09-08 | Consent | Access · rectify | Limited rules | Special-cat | Emerging | CNDP | — | →Stable | I |
| TUNTunisiaAfrica | Limited | Law 2004 (reform pending) | Consent | Access | Weak | Some | None | INPDP | — | →Reform pending | I |
| EGYEgyptAfrica | Limited | DP Law 2020 (regs pending) | Consent | Access | Weak | Some | Mandatory | Authority pending | — | ↑Regs pending | I |
| AREUAEMiddle East | Moderate | PDPL 2021 + DIFC/ADGM | Consent | Access · erase · port | Limited rules | Special-cat | Mandatory | UAE Data Office | — | ↑In force | I |
| SAUSaudi ArabiaMiddle East | Moderate | PDPL 2023 | Consent | Access · delete · port | Limited rules | Special-cat | Mandatory (72h) | SDAIA | — | ↑In force 2024 | I |
| QATQatarMiddle East | Moderate | PDPPL 2016 | Consent | Access · correct | Limited rules | Special-cat | Mandatory | NDPO | — | →First GCC law | I |
| BHRBahrainMiddle East | Moderate | PDPL 2018 | Consent | Access · correct | Limited rules | Special-cat | Mandatory | PDP Authority | — | →Stable | I |
| OMNOmanMiddle East | Moderate | PDPL 2022 | Consent | Access · correct | Limited rules | Special-cat | Mandatory | MTCIT | — | ↑In force 2023 | I |
| KWTKuwaitMiddle East | Limited | CITRA reg (2021) | Consent | Access | Weak | None | None | CITRA | — | →Sectoral only | I |
| IRQIraqMiddle East | Minimal | No comprehensive law | None | None | None | None | None | None | — | →Stable | I |
| IRNIranMiddle East | Minimal | No comprehensive law | None | None | None | None | None | None | — | →Draft bill | I |
| GHAGhanaAfrica | Moderate | DPA 2012 | Consent | Access · correct | Limited rules | Special-cat | Emerging | DP Commission | — | →Stable | I |
| KENKenyaAfrica | Substantial | DPA 2019 | Opt-in | Access · erase · port | Consent | Special-cat | 72h | ODPC · active | — | ↑Active regulator | I |
| NGANigeriaAfrica | Substantial | NDPA 2023 | Consent | Access · erase | Limited rules | Special-cat | 72h | NDPC | — | ↑NDPA 2023 | I |
| SENSenegalAfrica | Moderate | Law 2008 | Consent | Access · rectify | Weak | Special-cat | None | CDP | — | →Stable | I |
| ZMBZambiaAfrica | Limited | DP Act 2021 | Consent | Access · correct | Weak | Special-cat | Mandatory | New (2021) | — | ↑New 2021 law | I |
| ZWEZimbabweAfrica | Limited | Cyber & DP Act 2021 | Consent | Access | Weak | Some | Mandatory | POTRAZ | — | →Stable | I |
| UGAUgandaAfrica | Moderate | DPP Act 2019 | Consent | Access · correct | Weak | Special-cat | Mandatory | PDPO | — | →Stable | I |
| BWABotswanaAfrica | Moderate | DP Act 2018 | Consent | Access · correct | Weak | Special-cat | Emerging | Info & DP Commission | — | ↑In force 2021 | I |
| NAMNamibiaAfrica | Weak | Bill pending | None | None | None | None | None | None | — | ↑Bill pending | I |
| SGPSingaporeAsia–Pacific | Substantial | PDPA 2012 | Opt-in (consent) | Access · correct · port | Do-Not-Call + consent | Some | Mandatory (2021) | PDPC · active fines | — | →Active enforcer | I |
| MYSMalaysiaAsia–Pacific | Substantial | PDPA 2010 (2024 amd) | Consent | Access · correct | Limited rules | Special-cat | Mandatory (2024) | PDP Commissioner | — | ↑2024 amendments | I |
| PHLPhilippinesAsia–Pacific | Substantial | DPA 2012 | Consent | Access · erase · port | Consent | Special-cat | 72h (NPC) | NPC · active | — | →Active regulator | I |
| IDNIndonesiaAsia–Pacific | Moderate | PDP Law 2022 | Consent | Access · erase · port | Limited rules | Special-cat | 72h | Agency (forming) | — | ↑In force 2024 | I |
| THAThailandAsia–Pacific | Substantial | PDPA 2019 | Opt-in (consent) | Access · erase · port | Consent | Special-cat | 72h | PDPC | — | ↑In force 2022 | I |
| VNMVietnamAsia–Pacific | Substantial | PDPL 2025 | Opt-in (explicit) | Access · delete | Sale banned | Special-cat | Mandatory | MPS · up to 5% (state-run) | — | ↑In force Jan 2026 | I |
| LKASri LankaAsia–Pacific | Moderate | PDPA 2022 | Consent | Access · erase | Limited rules | Special-cat | Mandatory | DPA (new) | — | ↑New law | I |
| NPLNepalAsia–Pacific | Limited | Privacy Act 2018 | Consent | Access | Weak | Some | None | Weak | — | →Limited | I |
| KHMCambodiaAsia–Pacific | Weak | Draft law | None | None | None | None | None | None | — | ↑Draft law | I |
| MNGMongoliaAsia–Pacific | Moderate | PDP Law 2021 | Consent | Access · correct | Limited rules | Special-cat | Mandatory | New (2021) | — | ↑New 2021 law | I |
| PAKPakistanAsia–Pacific | Weak | Draft bill (pending) | None | None | None | None | None | None | — | →Bill pending | I |
| MMRMyanmarAsia–Pacific | Minimal | No DP law | None | None | None | None | None | None | — | →Junta rule | I |
| PRKNorth KoreaAsia–Pacific | Minimal | No law | None | None | None | None | None | None | — | →No open internet | I |
No countries in that tier.
Reading the columns. Comprehensive law is whether an omnibus statute covers the private sector, or only a sectoral patchwork does. Consent model is the default: opt-in with a lawful basis is more protective than opt-out. Access & deletion is what you can demand of a company — to see, correct, erase, and port your data. Sale & targeted ads is whether selling data or behavioural profiling needs your consent or an opt-out. Sensitive & children is the extra protection for health, biometric, and children’s data. Breach notice is whether a company must tell you and the regulator when your data leaks. Enforcement & penalty is the part that makes the rest real: an independent regulator and a fine large enough to matter. EU adequacy sits here because it is the external verdict on a country’s commercial regime — though Schrems II shows it also weighs state access, so it is not a pure consumer measure. Basis tags each row: P primary-source-driven, P·I mixed, I estimated from the tracker.Checked July 18, 2026 — verify current details before relying on this. General information, not legal advice.
Sources & notes (companies)
Each number matches a superscript in the table above and points to the primary instrument or regulator behind a documented cell. Cells without a number are estimated from the DLA Piper tracker (source 14) and shown in grey. Checked July 18, 2026.
- European Union — General Data Protection Regulation (Regulation (EU) 2016/679) — private-sector duties, the individual rights of access, erasure and portability, 72-hour breach notification, and fines up to 4% of global turnover, enforced by an independent authority. eur-lex.europa.eu
- European Commission — Adequacy decisions — the external verdict on a country’s data-protection regime; note that Schrems II turned on state access, so adequacy is not a purely commercial measure. commission.europa.eu
- United States — California Consumer Privacy Act / CPRA — rights to know, delete, and opt out of the sale or sharing of personal data, enforced by the California Privacy Protection Agency. There is no comprehensive federal statute: a sectoral patchwork (HIPAA, GLBA, COPPA, FCRA) plus a growing set of state laws. oag.ca.gov
- China — Personal Information Protection Law (PIPL), effective 1 November 2021 — separate opt-in consent, data minimisation, deletion and portability rights, strict facial-recognition rules, and fines up to 5% of turnover; enforced by the state Cyberspace Administration, not an independent regulator, and subject to broad state carve-outs. dlapiperdataprotection.com
- Brazil / European Commission — LGPD, enforced by the ANPD, and the EU–Brazil mutual adequacy decisions of January 2026. ec.europa.eu
- Japan — Act on the Protection of Personal Information (APPI), enforced by the independent Personal Information Protection Commission; the first post-GDPR adequacy country. ppc.go.jp
- South Korea — Personal Information Protection Act (PIPA). The Personal Information Protection Commission (independent since 2020) has fined Google and Meta tens of millions of dollars; Korea holds EU adequacy. pipc.go.kr
- United Kingdom — UK GDPR as amended by the Data (Use and Access) Act 2025 (Royal Assent 19 June 2025) — it keeps the comprehensive framework and EU adequacy while easing some rules (recognised legitimate interests, automated decisions) and adding children’s-protection duties and a right to complain to controllers; enforced by the ICO. legislation.gov.uk
- India — Digital Personal Data Protection Act 2023 — consent-based with parental consent for children, but not yet in force, with broad government exemptions and a non-independent Data Protection Board. dlapiperdataprotection.com
- South Africa — Protection of Personal Information Act (POPIA), enforced by the Information Regulator; mandatory breach notification and consent-based direct marketing. inforegulator.org.za
- Switzerland — Revised Federal Act on Data Protection (in force 1 September 2023), GDPR-aligned, enforced by the FDPIC; Switzerland holds EU adequacy. edoeb.admin.ch
- Canada — Personal Information Protection and Electronic Documents Act (PIPEDA), enforced by the Office of the Privacy Commissioner (limited fining power; the Bill C-27 reform lapsed); EU adequacy for commercial data. priv.gc.ca
- Australia — Privacy Act 1988 (Australian Privacy Principles) and the Notifiable Data Breaches scheme, enforced by the OAIC; the Privacy and Other Legislation Amendment Act 2024 began a phased strengthening. oaic.gov.au
- DLA Piper — Data Protection Laws of the World — the cross-country tracker behind the estimated (Basis “I”) rows and tier placements; the commercial-privacy analog to the internet-freedom index used in the first table. dlapiperdataprotection.com
On method. Tiers, not scores, for the same reason as the first table: the top and bottom are robust, the middle turns on how you weigh paper rights against real enforcement. This is a student project for privacy education; it is not an official index and takes no position on any government.
What the pattern shows
Courts, alliances, and the gap between law and operation
The top tier has a common feature, and it isn’t a privacy law on the books — almost every country has one of those. It’s an independent court willing to strike surveillance powers down. The countries in the strongest tier tend to pair a data-protection statute with a constitutional court that has actually voided a retention mandate or an intelligence power, so the protection holds when a government would rather it didn’t. A statute a legislature can quietly amend is worth less than the same words a court will enforce.
Intelligence-sharing membership caps how high an otherwise-strong democracy can sit. A country can have GDPR-grade law and an active regulator and still run bulk-collection powers or cable interception under a national-security carve-out. Where it does, the table places it a tier below what its commercial protections alone would suggest — which is why several wealthy democracies with excellent consumer-privacy regimes land in the middle rather than the top. The companion table above is where that strength reappears: the UK, the United States, and Australia all sit markedly higher against companies than against their own governments.
One reading needs care, and it’s the reason scores were dropped. A repressive law on the books is not the same as a sealed network in operation. Several states with sweeping surveillance statutes still run comparatively open networks in practice — filtering incomplete, VPN use widespread, no permanent isolation actually achieved — while a smaller set operate the control they legislate. The tiers reflect what a person can actually do, so a legally repressive but operationally leaky regime can sit above a fully operational one. The Trend column carries the direction of travel, which is often where the real story is.
And the honest limit: about a fifth of the rows are documented cell-by-cell; the rest are estimates, and roughly a quarter of all countries fall outside the index this leans on entirely. The Basis tag and the grey markers are there so you can see exactly which is which — the same discipline as our campus transparency table, where an unanswered question is marked, not guessed.
Sources & notes
Each number matches a superscript in the table and points to the primary instrument behind a documented cell. Cells without a number are either a finding of absence or an estimate from the index in source 12 — there’s no single document to link. The estimated rows (Basis I) rest chiefly on that index plus EU-adequacy status and public data-protection-law trackers; they carry no per-country primary source, and roughly a quarter of the list sits outside the index’s 72 countries on the thinnest basis of all. Checked July 11, 2026.
- European Union — General Data Protection Regulation (Regulation (EU) 2016/679) — the statutory data-protection framework, and the requirement of an independent supervisory authority, binding in every member state. eur-lex.europa.eu
- Court of Justice of the EU — Digital Rights Ireland (2014) struck the blanket Data Retention Directive; La Quadrature du Net (2020) held that general, indiscriminate retention is unlawful save under narrow conditions — the case-law behind the “court-struck” retention cells across the EU. curia.europa.eu (PDF)
- European Commission — Adequacy decisions — the official list of non-EU jurisdictions recognised as providing adequate data protection (Japan, South Korea, Argentina, Uruguay, Canada (commercial), the UK, and others). commission.europa.eu
- Germany · Federal Constitutional Court — Judgment of 1 October 2024 (Press Release 83/2024): storage powers under §18(1) no.2 and contact-person surveillance under §45(1) no.4 of the BKA Act held incompatible with the right to informational self-determination, effective until 31 July 2025. bundesverfassungsgericht.de
- Germany · Federal Constitutional Court — Order of 8 October 2024: strategic cyber-surveillance of international telecommunications by the Federal Intelligence Service (BND) held unconstitutional in part. bundesverfassungsgericht.de
- Switzerland — Federal Constitution Art. 13 and the Federal Act on Data Protection (2023). The 2025 revision of the OSCPT/VÜPF surveillance ordinance would add mandatory identification, six-month retention, and — under Art. 50a — a duty to remove provider-applied encryption; Proton has said it would relocate infrastructure in response. swissinfo.ch
- United Kingdom — Investigatory Powers Act 2016 — bulk powers, 12-month Internet Connection Record retention, and secret Technical Capability Notices (the mechanism behind the Apple encryption demand). legislation.gov.uk
- United Kingdom — Online Safety Act 2023 — “highly effective age assurance” duties, in force from 25 July 2025. legislation.gov.uk
- United States · Congress — Congressional Research Service R48592 on FISA Section 702 and the 2024 RISAA: reauthorised 20 April 2024, broadened the “electronic communication service provider” definition, sunsets 20 April 2026. The US has no comprehensive federal privacy statute. congress.gov
- Australia — Telecommunications (Assistance and Access) Act 2018 (decryption-assistance regime) and the mandatory metadata-retention scheme under the Telecommunications (Interception and Access) Act. legislation.gov.au
- Russia · documentation — Human Rights Watch, Disrupted, Throttled, and Blocked (2025) — documents SORM, the 2019 “sovereign internet” law and Yarovaya retention, and that filtering/isolation remain incomplete in practice (the basis for the operational-vs-legal reading). hrw.org
- Freedom House — Freedom on the Net 2025 — the cross-country internet-freedom index behind the estimated (Basis “I”) rows and the tier placements; it also documents China and Myanmar as the worst environments and the UK’s 2025 demands to Apple. It assesses 72 countries, so the roughly 28 outside it rest on the thinnest basis of all. freedomhouse.org
- Brazil / European Commission — Brazil’s LGPD and the EU–Brazil mutual adequacy decisions of 26–27 January 2026 (European Commission Implementing Decision (EU) 2026/179; ANPD Resolution No. 32/2026). ec.europa.eu
- Japan — Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, amended 2020), enforced by the independent Personal Information Protection Commission; Japan was the first country to receive an EU adequacy decision after the GDPR. ppc.go.jp
- South Korea — Personal Information Protection Act (PIPA, 2011). The 2020 amendment made the Personal Information Protection Commission an independent regulator, which has fined Google and Meta tens of millions of dollars; privacy is a constitutional right and Korea holds EU adequacy. pipc.go.kr
- India · Supreme Court — K. S. Puttaswamy v. Union of India (2017) held privacy to be a fundamental right under Article 21; the Digital Personal Data Protection Act 2023 grants broad state exemptions and a non-independent board, and the Aadhaar programme is a mass biometric-identity system. globalfreedomofexpression.columbia.edu
- China — Personal Information Protection Law (PIPL), effective 1 November 2021 — a comprehensive statute that binds companies (including rules on facial-recognition use) but does not constrain state surveillance. dlapiperdataprotection.com
- South Africa · Constitutional Court — amaBhungane v Minister of Justice [2021] ZACC 3 (4 February 2021) held RICA’s bulk interception unlawful and the Act unconstitutional in five respects; POPIA (Act 4 of 2013) and Constitution §14 protect privacy. saflii.org
- European Union — Regulation (EU) 2021/1232, the temporary ePrivacy derogation permitting voluntary provider scanning of non-encrypted communications for known CSAM. Lapsed 3 April 2026; reinstated 9 July 2026 to run until 3 April 2028; it does not reach end-to-end-encrypted messages. eur-lex.europa.eu
- European Parliament — Press release on the 9 July 2026 second-reading vote (“Combating child sexual abuse: support for a more limited ePrivacy derogation”): the motion to reject the Council position drew 314 votes to 276, short of the 361-vote absolute majority needed to block it, so the derogation stands. The permanent Child Sexual Abuse Regulation, COM(2022) 209, remains in trilogue. europarl.europa.eu
- United States — 18 U.S.C. § 2258A. Providers are not required to search for CSAM but may scan voluntarily (hash-matching on non-encrypted surfaces such as Gmail, Messenger, and cloud storage) and must report anything found to NCMEC’s CyberTipline. law.cornell.edu
- United Kingdom — Online Safety Act 2023, s.121 (the former cl.122 “spy clause”): Ofcom may issue a Technology Notice requiring a provider to use “accredited technology” to scan for CSEA or terrorism content, including on end-to-end-encrypted services. The power is not yet exercised — the government has said it will not be used until “technically feasible,” and no technologies had been accredited as of mid-2026. ofcom.org.uk
On method. Tiers replace the exact scores from the underlying research, because a five-tier range is far more defensible than a precise 1-to-100 ordering — the top and bottom are robust, the middle is sensitive to how you weigh state surveillance against commercial protection. This is a student project for privacy education; it is not an official index, and it takes no position on any government.
Get involved
It’s free, open to everyone at Pitt, and joining takes about a minute.
No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.