Last reviewed April 2026

Privacy Law Comparison — 2026

Side-by-side comparison of GDPR, UK GDPR, CCPA/CPRA, PIPEDA, Quebec Law 25, LGPD, Australian Privacy Act, India DPDP, and UAE PDPL.

Scroll horizontally on mobile to view all columns. Click any law's column header to view its full guide.

AttributeGDPRUK GDPRCCPA/CPRAPIPEDAQuebec Law 25LGPDAustralian PAIndia DPDPUAE PDPL
JurisdictionEU/EEA (27 states)United KingdomCalifornia, USACanada (federal)Quebec, CanadaBrazilAustraliaIndiaUnited Arab Emirates
Who it applies toAny org processing EU data regardless of locationAny org processing UK data regardless of locationFor-profit businesses meeting revenue/volume thresholdsPrivate sector commercial organisationsAll organisations collecting Quebec resident dataAny org processing Brazil data regardless of locationOrgs with >AUD $3M turnover + exempt categoriesAny org processing India digital personal dataAny org processing UAE data regardless of location
Consent modelOpt-in (one of 6 legal bases)Opt-in (one of 6 legal bases)Opt-out (notice + right to opt-out)Meaningful consent (opt-in)Opt-in (explicit consent for secondary use)Opt-in (one of 10 legal bases)Notice-based (consent + legitimate interests)Opt-in (explicit consent required)Opt-in (consent + legitimate interests)
Right to accessYes — Art. 15 GDPRYes — Art. 15 UK GDPRYes — Cal. Civ. Code §1798.100Yes — PIPEDA Principle 9Yes — s.28Yes — LGPD Art. 18(I)Yes — APP 12Yes — DPDP s.11Yes — UAE PDPL Art. 12
Right to erasureYes — Art. 17 GDPRYes — Art. 17 UK GDPRYes — Cal. Civ. Code §1798.105Limited — PIPEDAYes — s.28.1Yes — LGPD Art. 18(VI)Yes — APP 11.2Yes — DPDP s.12Yes — UAE PDPL Art. 13
Right to portabilityYes — Art. 20 GDPRYes — Art. 20 UK GDPRNo — not a CCPA rightNoYes — s.28.1Yes — LGPD Art. 18(V)Limited — under reviewPending rulesNo
Automated decisions opt-outYes — Art. 22 GDPRYes — Art. 22 UK GDPRYes — sensitive PI limit useNoYes — s.12Yes — LGPD Art. 20Yes — effective Dec 2026Pending rulesPending regulations
Breach notification deadline72 hours to DPA72 hours to ICONo fixed windowAs soon as feasible72 hours to CAIPrompt (2 business days)30 days to OAIC72 hours expected72 hours to TDRA
Max penalty€20M or 4% global revenue£17.5M or 4% global revenue$7,988 per intentional violationCAD $100,000CAD $25M or 4% global revenue2% revenue or R$50MAUD $50,000,000₹250 crore per instanceAED 5M–20M
DPO/Privacy Officer requiredYes — in certain cases (Art. 37)Yes — in certain casesNo — but CPO recommendedYes — Privacy OfficerYes — mandatory (s.3.1)Yes — Encarregado (Art. 41)No — but recommendedYes — for Significant FiduciariesNo — not mandatory
Children's age threshold16 (or 13–16 with member state option) — Art. 813 (UK DPA 2018 s.9)16 (opt-in) / 13 under COPPA13 (default under PIPEDA)14 — s.4.118 (consent) / stricter rules15 (proposed reforms)18 (DPDP Act s.9)Pending regulations
Supervisory authorityNational DPAs (EDPB coordination)ICO (Information Commissioner)California Privacy Protection AgencyOffice of Privacy Commissioner (OPC)Commission d'accès à l'information (CAI)Autoridade Nacional de Proteção de Dados (ANPD)Office of Australian Info Commissioner (OAIC)Data Protection Board of IndiaUAE TDRA

Data correct as of April 2026. Some jurisdictions have pending rule-making that may alter obligations. Not legal advice — always verify with official sources.

Find out which of these laws apply to your business

Run the free assessment to get a personalised privacy law checklist with exact statutory citations — in under 4 minutes.

Start free assessment →