Reviewed by: Mansoor Ali, Technical Editor, PenPonder | Last Updated: July 2026
144 countries now have national data privacy laws. 20 US states have comprehensive privacy legislation. The EU has issued over €6.7 billion in GDPR fines since 2018. And the EU AI Act added an entirely new compliance layer from August 2, 2026.
The complexity is real. But most businesses do not need to understand all 144 laws. They need to understand the ones that apply to their specific situation and what those laws actually require them to do.
This guide cuts through the complexity. It identifies the laws most likely to apply to your business, explains what each requires in plain English, and gives you a practical starting point for building or improving your compliance programme.
The Data Protection Landscape in 2026
- 144 countries have enacted national data privacy laws as of 2026
- 20 US states have comprehensive consumer privacy laws in effect as of July 2026. There is still no federal privacy law.
- GDPR has produced over €6.7 billion in cumulative fines since 2018, with 2,679 enforcement actions recorded
- Three new US state laws took effect on January 1, 2026: Indiana, Kentucky, and Rhode Island
- 400+ GDPR breach notifications are filed daily with European regulators
- 82% of internet users are concerned about data collection practices
- 48% have already changed purchasing behaviour based on privacy practices
- California’s CCPA fines increased in 2025 to $7,988 per intentional violation, with no automatic cure period
- Disney paid $2.75 million in the largest CCPA settlement in California history in February 2026
- TikTok received €530 million in GDPR fines for illegal data transfers to China in 2025
Which Laws Apply to Your Business
Before building any compliance programme, you need to know which laws actually apply to you. The answer depends on four factors: where your customers are located, what type of data you collect, the size of your business, and what you do with the data.
| If you have… | Then you likely need… | Key requirement |
|---|---|---|
| Customers or employees in the EU or EEA | GDPR compliance | Lawful basis for processing, 72-hour breach notification, data subject rights |
| Customers in California (for-profit, over $25M revenue OR 100K+ consumers) | CCPA/CPRA compliance | Privacy notice, opt-out rights, data deletion on request |
| Customers in any of 19 other US states with privacy laws | State-specific compliance | Access, deletion, correction, and opt-out rights vary by state |
| US patient health information | HIPAA compliance | BAA with vendors, PHI encryption, access controls, breach notification |
| Payment card data from any customer | PCI DSS v4.0 | Network security, access controls, encryption, quarterly vulnerability scans |
| Customers in Brazil | LGPD compliance | Lawful basis, data subject rights, DPA notification of breaches |
| Customers in Canada | PIPEDA or Quebec Law 25 | Consent, breach notification, privacy officer designation |
| AI systems used in the EU | EU AI Act compliance | From August 2, 2026: transparency, documentation, human oversight |
The most important principle: data protection laws follow the data subject, not the company. GDPR applies to any business anywhere in the world that processes data belonging to EU residents. You do not need to be based in the EU. You do not need to have an office in the EU. If you have EU customers, GDPR applies to you.
The same extraterritorial principle applies to most modern privacy laws. CCPA applies to businesses with California customers meeting certain thresholds, regardless of where the company is headquartered.
What Does GDPR Compliance Require in 2026?
The General Data Protection Regulation is the most influential data privacy law in the world. It took effect in May 2018 and has shaped data protection legislation in dozens of countries that modelled their own laws on its principles.
GDPR applies to any organisation that processes personal data of EU or EEA residents, regardless of where the organisation is located. There is no revenue minimum and no size exemption. A one-person startup with EU customers must comply with GDPR.
What GDPR Requires
Lawful basis for processing. Every time you process personal data, you need a legal justification. The six lawful bases are: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Most businesses rely primarily on consent and contract performance. Legitimate interests requires a balancing test documenting that your interests do not override the individual’s rights.
Data subject rights. Individuals have the right to access their data, correct inaccurate data, delete their data in certain circumstances, restrict processing, data portability, and object to processing. You must be able to fulfil these requests within one month.
Privacy notices. You must tell people what data you collect, why you collect it, how long you keep it, who you share it with, and what rights they have. Privacy notices must be clear, concise, and in plain language.
Breach notification. You must notify your supervisory authority within 72 hours of becoming aware of a breach that is likely to result in risk to individuals’ rights and freedoms. If the breach is likely to result in high risk, you must also notify affected individuals without undue delay.
Data Protection Impact Assessments. For processing that is likely to result in high risk, you must conduct a DPIA before the processing begins. This includes large-scale processing of sensitive data, systematic monitoring of public areas, and automated decision-making with significant effects.
Data transfers outside the EEA. Transferring personal data to countries outside the EEA requires either an adequacy decision (the country’s laws provide equivalent protection) or appropriate safeguards such as Standard Contractual Clauses. The US operates under the EU-US Data Privacy Framework, renewed until 2031.
GDPR Enforcement in 2026
The most common GDPR violations resulting in fines are: insufficient legal basis for processing, non-compliance with general data processing principles, and insufficient security measures. Spain leads enforcement actions with 1,033 cases. Ireland has issued the largest fines due to hosting major technology companies.
A common misconception is that GDPR only targets large technology companies. Spain issues the majority of its fines against mid-market companies, retailers, energy companies, and employers. GDPR enforcement reaches businesses of all sizes.
CCPA and CPRA Compliance Requirements for US Businesses
California’s Consumer Privacy Act, amended and strengthened by the Consumer Privacy Rights Act, is the most comprehensive US privacy law and the de facto standard for US state privacy compliance.
CCPA applies to for-profit businesses that meet one or more of these thresholds: annual gross revenue over $25 million, processing data of 100,000 or more California consumers or households per year, or deriving 50% or more of annual revenue from selling California consumers’ personal information.
What CCPA/CPRA Requires
Consumer rights. California residents have the right to know what personal information a business collects about them, the right to delete their personal information, the right to opt out of the sale or sharing of their personal information, the right to correct inaccurate personal information, and the right to limit use of sensitive personal information.
Privacy notice. Businesses must provide a privacy notice at or before the point of data collection. The notice must disclose what categories of personal information are collected and for what purposes.
Opt-out mechanism. Businesses that sell or share personal information must provide a clear and conspicuous “Do Not Sell or Share My Personal Information” link. Eight US states now mandate support for universal opt-out signals like Global Privacy Control.
Data retention limits. Businesses cannot retain personal information longer than reasonably necessary for the disclosed purpose.
Security requirements. From January 2026, new CPPA regulations require mandatory cybersecurity audits and risk assessments for automated decision-making technology. For a step-by-step breakdown of the frameworks that structure these assessments, see our Cybersecurity Frameworks 2026 guide.
CCPA Enforcement in 2026
California’s Privacy Protection Agency has become significantly more active. The $1.35 million fine against Tractor Supply Company in 2025 targeted a non-functioning “Do Not Sell” mechanism. The $2.75 million Disney settlement in February 2026 for CCPA opt-out failures was the largest in state history at that time.
Penalties now range from $2,663 per negligent violation to $7,988 per intentional violation, with no automatic cure period for intentional violations. A company with 100,000 affected consumers could face theoretical exposure approaching $800 million for large-scale intentional violations.
The US State Privacy Law Patchwork in 2026
With no federal privacy law, US businesses operating nationally must navigate 20 state laws that share common principles but differ in important details.
| State | Law | Effective | Notable Feature |
|---|---|---|---|
| California | CCPA/CPRA | Jan 2020 / Jan 2023 | Strictest in US, covers employee and B2B data, dedicated regulator |
| Virginia | VCDPA | Jan 2023 | Virginia model used as template by many states |
| Colorado | CPA | Jul 2023 | Requires universal opt-out signal support |
| Connecticut | CTDPA | Jul 2023 | TicketNetwork fined $85,000 in 2025 for non-compliant privacy notice |
| Texas | TDPSA | Jul 2024 | No private right of action, AG enforcement only |
| Florida | FDBR | Jul 2024 | Applies to large businesses only, over $1 billion revenue |
| Oregon | OCPA | Jul 2024 | Broader definition of sensitive data |
| Maryland | MODPA | Apr 2026 | Strictest data minimisation standard in US |
| Indiana | INCDPA | Jan 2026 | Virginia model, controller duties reinforced |
| Kentucky | KCDPA | Jan 2026 | Business-friendly, permanent cure period |
| Rhode Island | RIDTPPA | Jan 2026 | Virginia model, applies to 100,000+ consumers threshold |
Most state laws apply similar thresholds: businesses processing data of 100,000 or more state residents, or 25,000 or more residents when data sales generate over 50% of revenue. This means many small businesses fall outside state law requirements. The exception is California, which has the lowest thresholds and the broadest coverage.
The common rights across all 20 state laws: access, correction, deletion, portability, and opt-out of targeted advertising, data sales, and profiling in significant decisions. The differences lie in thresholds, cure periods, enforcement mechanisms, and definitions of sensitive data.
Other Global Privacy Laws That May Apply to Your Business
Brazil LGPD. The Lei Geral de Proteção de Dados mirrors GDPR’s structure with lawful bases, data subject rights, and a national data protection authority. Fines cap at 2% of Brazilian annual revenue up to BRL 50 million per infraction. The ANPD has expanded enforcement significantly in 2025 and 2026.
Canada PIPEDA and Quebec Law 25. PIPEDA is Canada’s federal privacy law governing commercial organisations. Quebec’s Law 25 is stricter with GDPR-scale penalties reaching CAD 25 million or 4% of worldwide turnover. It is the strictest privacy law in North America outside California.
UK GDPR. Post-Brexit, the UK operates its own version of GDPR with equivalent requirements. The EU-UK adequacy decision was renewed until 2031, allowing data to flow freely between the EU and UK without additional transfer mechanisms.
India DPDP Act. India’s Digital Personal Data Protection Act is being phased in during 2026. Phase 2 and Phase 3 rollout requires consent manager registration by November 13, 2026. Fines range from ₹50 crore to ₹250 crore per violation.
China PIPL. China’s Personal Information Protection Law matches or exceeds GDPR in specific areas including data localisation requirements and mandatory cross-border transfer assessments. Fines can reach 5% of annual revenue.
The EU AI Act: A New Data Compliance Layer in 2026
The EU AI Act adds compliance obligations that intersect directly with data protection. August 2, 2026 is the enforcement date for general-purpose AI model obligations and Article 50 transparency requirements.
For businesses using AI systems that process personal data, the intersection of GDPR and EU AI Act creates specific obligations:
- AI systems that interact with individuals must disclose that they are AI
- Personal data used to train AI models must have a lawful basis under GDPR
- High-risk AI systems require both a GDPR Data Protection Impact Assessment and an EU AI Act conformity assessment
- Automated decision-making with significant effects on individuals requires both GDPR Article 22 compliance and AI Act documentation requirements
- AI training data must be documented for provenance, accuracy, and bias assessment
63% of organisations lack AI governance policies according to IBM research. This gap is becoming increasingly expensive. California’s updated CCPA framework now requires privacy risk assessments for automated decision-making technology. The EU AI Act enforcement from August 2026 makes documentation and transparency obligations legally mandatory rather than best practice.
For a full breakdown of EU AI Act requirements see our EU AI Act and GDPR compliance guide. For the broader AI compliance framework see our 2026 AI Compliance Guide.
Despite the geographic and regulatory variation, most data protection laws share the same underlying principles. Understanding these principles gives you a foundation that applies across multiple frameworks simultaneously.
1. Lawfulness and transparency. Data must be collected and processed with a legal basis and individuals must know what is happening with their data. This principle appears in GDPR, CCPA, LGPD, PIPL, and every major state law.
2. Purpose limitation. Data collected for one purpose cannot be used for an incompatible purpose without additional consent or legal basis. This prevents the scope creep that occurs when data collected for service delivery is later used for unrelated marketing.
3. Data minimisation. Collect only what is necessary for the stated purpose. No more. Maryland’s MODPA is the strictest implementation of this principle in US law, but all major frameworks include it in some form.
4. Accuracy. Personal data must be kept accurate and up to date. Individuals have the right to correct inaccurate data in almost every major framework.
5. Storage limitation. Data cannot be kept longer than necessary for the purpose for which it was collected. Clear retention schedules with documented justification are required.
6. Security. Appropriate technical and organisational measures must protect personal data against unauthorised access, loss, or destruction. What counts as appropriate depends on the sensitivity of the data and the risks involved.
7. Accountability. Organisations must be able to demonstrate compliance. This means documentation, policies, records of processing activities, and audit trails. Saying you are compliant is not enough. Being able to prove it is the requirement.
8. Individual rights. Individuals have rights over their data. The specific rights vary by jurisdiction but commonly include access, correction, deletion, and opt-out of certain uses. Building processes to handle rights requests within regulatory timelines is a practical requirement for every compliant organisation.
Building a Data Protection Compliance Programme That Covers Multiple Laws
Most organisations face multiple data protection laws simultaneously. The practical approach is to build a single compliance programme anchored to the strictest applicable law and verify it covers the requirements of all others.
For businesses with EU customers, GDPR is typically the strictest applicable framework. A GDPR-compliant programme provides substantial coverage for US state law compliance, LGPD, UK GDPR, and most other modern privacy laws because they share the same core principles.
Step 1: Map your data. Know what personal data you hold, where it came from, what you do with it, who you share it with, and how long you keep it. This data map is the foundation of every compliance programme and the first thing regulators ask for during investigations.
Step 2: Identify which laws apply. Use the table at the top of this guide as a starting point. For each law that applies, document the specific requirements and how your current practices measure against them.
Step 3: Establish lawful bases for processing. For each category of personal data you process, document the lawful basis. For GDPR, this means selecting from the six bases and maintaining records. For US state laws, this means ensuring you have appropriate notice and consent mechanisms.
Step 4: Build rights request processes. Create processes to handle access requests, deletion requests, correction requests, and opt-out requests within regulatory timelines. GDPR requires one month. Most US state laws require 45 days with a possible 45-day extension.
Step 5: Implement consent management. Deploy a consent management platform that handles cookie consent, marketing consent, and data processing consent across the jurisdictions you serve. Eight US states now mandate support for Global Privacy Control signals. GDPR requires equal prominence for accept and reject options.
Step 6: Create a breach response process. GDPR requires authority notification within 72 hours. Most US state laws require customer notification within 30 to 90 days depending on the state. Know your notification obligations before a breach occurs, not during one.
Step 7: Train your people. Data protection compliance depends on employees handling data correctly. Training on what data they can collect, how they can use it, and how to handle requests and incidents is a requirement, not a nice-to-have.
For how data protection compliance connects to cybersecurity frameworks and controls, see our Cybersecurity Frameworks 2026 guide and our Cloud Security Compliance guide.
Final Verdict
The data protection compliance landscape in 2026 is genuinely complex. 144 countries with laws. 20 US states. GDPR with €6.7 billion in fines. A new AI compliance layer from August 2026. Three new US state laws effective January 1, 2026.
But the underlying principles are consistent. Collect only what you need. Tell people what you are doing with their data. Give them control over it. Keep it secure. Respond to requests within the required timeframes. Document everything.
An organisation that builds its compliance programme around those eight core principles, anchored to the strictest law that applies to it, will find that most other applicable laws are substantially covered by that same programme.
The businesses that get into trouble are not typically the ones that tried to comply and got something wrong. They are the ones that assumed the complexity was too great to address, did nothing, and then faced regulators with no documentation, no policies, and no processes to show.
Start with identifying which laws apply. Build a data map. Document your lawful bases. Create rights request processes. The compliance programme builds from those foundations.
Frequently Asked Questions
Which data protection laws apply to my business?
It depends on where your customers are located, what data you collect, and your business size. If you have EU customers, GDPR applies regardless of where your company is based. If you have California customers and meet the revenue or data volume thresholds, CCPA applies. If you handle US health data, HIPAA applies. If you process payment cards, PCI DSS applies. Most businesses are subject to multiple laws simultaneously.
What is the difference between GDPR and CCPA?
GDPR applies to any organisation processing data of EU residents, with no size threshold. CCPA applies to for-profit California businesses meeting specific revenue or data volume thresholds. GDPR is generally considered stricter: it requires a lawful basis for all processing, has broader individual rights, and produces larger fines. Both require privacy notices, breach notification, and mechanisms for individuals to exercise their rights.
How many US states have data privacy laws in 2026?
20 US states have comprehensive consumer privacy laws in effect as of July 2026. There is no federal privacy law. The 20 states share common rights frameworks based largely on the Virginia model, but differ in thresholds, enforcement mechanisms, sensitive data definitions, and cure periods. California remains the strictest with the lowest thresholds and a dedicated privacy regulator.
What happens if I do not comply with data protection laws?
The consequences vary by law and severity. GDPR fines reach €20 million or 4% of global annual turnover. EU AI Act fines reach €35 million or 7% of global annual turnover. CCPA fines reach $7,988 per intentional violation. Beyond fines, non-compliance risks reputational damage, lost business from buyers requiring compliance documentation, and operational disruption from regulatory investigations.
Do small businesses need to comply with data protection laws?
It depends on the specific law. GDPR has no size exemption. If you have EU customers, it applies regardless of your company size. US state laws mostly apply to businesses processing data of 100,000 or more residents, so smaller businesses often fall below thresholds. HIPAA applies to covered entities regardless of size. Check each applicable law’s specific thresholds for your situation.
What is the EU AI Act and how does it relate to data protection?
The EU AI Act is the world’s first comprehensive AI regulation. It intersects with data protection because AI systems that process personal data must comply with both GDPR and AI Act requirements. From August 2, 2026, general-purpose AI model obligations and chatbot transparency requirements are enforceable. Fines reach €35 million or 7% of global annual turnover for prohibited practices.
For AI-specific and industry-specific compliance requirements on top of general data protection law, see our Compliance Guide.
Statistics sourced from IAPP US State Privacy Legislation Tracker, CookieScript GDPR enforcement data, O’Melveny 2026 Data Privacy Compliance Checklist, StationX Data Privacy Statistics 2026, CDP.com International Privacy Laws Reference, and SecurePrivacy 2026 Privacy Laws Guide. PenPonder does not provide legal advice. Organisations should consult qualified privacy counsel for jurisdiction-specific compliance questions.

