Laws and Major Regulations Related to Privacy

United States

Note: This list is representative and not to be considered an exhaustive listing.1 State laws and industry regulations may apply to your organization. Consult your legal counsel for definitive research.

Americans with Disabilities Act (ADA)

Cable Communications Policy Act of 1984 (Cable Act)

California Senate Bill 1386 (SB 1386)

Children's Internet Protection Act of 2001 (CIPA)

Children's Online Privacy Protection Act of 1998 (COPPA)

Communications Assistance for Law Enforcement Act of 1994

Computer Fraud and Abuse Act of 1986 (CFAA)

Computer Security Act of 1987: superseded by the Federal Information Security Management Act (FISMA)

Consumer Credit Reporting Reform Act of 1996 (CCRRA): modifies the Fair Credit Reporting Act (FCRA)

Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act of 2003

Driver's Privacy Protection Act of 1994

Electronic Communications Privacy Act of 1986 (ECPA)

Electronic Freedom of Information Act of 1996 (E-FOIA)

Electronic Funds Transfer Act (EFTA)

Fair and Accurate Credit Transactions Act (FACTA) of 2003

Fair Credit Reporting Act of 1999 (FCRA)

Family Education Rights and Privacy Act of 1974 (FERPA; aka the Buckley Amendment)

Federal Information Security Management Act (FISMA)

Federal Trade Commission Act (FTCA)

Gramm–Leach–Bliley Financial Services Modernization Act of 1999 (GLBA)

Privacy Act of 1974: including U.S. Department of Justice Overview

Privacy Protection Act of 1980 (PPA)

Right to Financial Privacy Act of 1978 (RFPA)

Telecommunications Act of 1996

Telephone Consumer Protection Act of 1991 (TCPA)

Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (USA-PATRIOT Act)

Video Privacy Protection Act of 1988

Major Privacy Laws Worldwide, by Country

Note: This list is representative and not to be considered an exhaustive listing.2 State or provincial laws and industry regulations may apply to your organization. Consult your legal counsel for definitive research.

Argentina. Personal Data Protection Act of 2000 (aka Habeas Data)

Australia. Privacy Act of 1988

Austria. Data Protection Act 2000, Austrian Federal Law Gazette part I No. 165/1999 (Datenschutzgesetz 2000 or DSG 2000)

Belgium. Belgium Data Protection Law

Brazil. Privacy currently governed by Article 5 of the 1988 Constitution

Bulgaria. Bulgarian Personal Data Protection Act

Canada. Privacy Act—July 1983 Personal Information Protection and Electronic Data Act (PIPEDA) of 2000 (Bill C-6)

Chile. Act on the Protection of Personal Data, August 1998

Colombia. Law 1266 of 2008: (in Spanish) and Law 1273 of 2009 (in Spanish)

Czech Republic. Act on Protection of Personal Data (April 2000) No. 101

Denmark. Act on Processing of Personal Data, Act No. 429, May 2000

Estonia. Personal Data Protection Act of 2003. (June 1996, Consolidated July 2002)

European Union. European Union Data Protection Directive of 1998; EU Internet Privacy Law of 2002 (Directive 2002/58/EC)

Finland. Act on the Amendment of the Personal Data Act (986) 2000

France. Data Protection Act of 1978 (revised in 2004)

Germany. Federal Data Protection Act of 2001

Greece. Law No. 2472 on the Protection of Individuals with Regard to the Processing of Personal Data, April 1997

Guernsey. Data Protection (Bailiwick of Guernsey) Law of 2001

Hong Kong. Personal Data Ordinance (the Ordinance)

Hungary. Act LXIII of 1992 on the Protection of Personal Data and the Publicity of Data of Public Interests

Iceland. Act of Protection of Individual; Processing Personal Data, January 2000

Ireland. Data Protection (Amendment) Act, Number 6, of 2003

India. Information Technology Act of 2000

Italy. Processing of Personal Data Act, January 1997; Data Protection Code of 2003

Japan. Personal Information Protection Law (Act) Law for the Protection of Computer Processed Data Held by Administrative Organs, December 1988

Korea. Act on Personal Information Protection of Public Agencies Act on Information and Communication Network Usage

Latvia. Personal Data Protection Law, March 2000

Lithuania. Law on Legal Protection of Personal Data, June 1996

Luxembourg. Law of August 2002 on the Protection of Persons with Regard to the Processing of Personal Data

Malaysia. Common Law Principle of Confidentiality Personal Data Protection Bill Banking and Financial Institutions Act of 1989 Privacy Provisions

Malta. Data Protection Act (Act XXVI of 2001), amended March 22, 2002, November 15, 2002 and July 15, 2003

Mexico. Federal Law for the Protection of Personal Data Possessed by Private Persons (Spanish)

Morocco. Data Protection Act

Netherlands. Dutch Personal Data Protection Act 2000 as amended by Acts dated April 5, 2001, Bulletin of Acts, Orders and Decrees 180, December 6, 2001

New Zealand. Privacy Act, May 1993; Privacy Amendment Act, 1993; Privacy Amendment Act, 1994

Norway. Personal Data Act (April 2000)–Act of April 14, 2000 No. 31 Relating to the Processing of Personal Data (Personal Data Act)

Philippines. Data Privacy Act of 2011 (There is also a recognized right of privacy in civil law and a model data protection code.)

Romania. Law No. 677/2001 for the Protection of Persons Concerning the Processing of Personal Data and the Free Circulation of Such Data

Poland. Act of the Protection of Personal Data (August 1997)

Portugal. Act on the Protection of Personal Data (Law 67/98 of 26 October)

Singapore. E-commerce Code for the Protection of Personal Information and Communications of Consumers of Internet Commerce

Slovak Republic. Act No. 428 of July 3, 2002, on Personal Data Protection

Slovenia. Personal Data Protection Act, RS No. 55/99

South Africa. Electronic Communications and Transactions Act, 2002

South Korea. Act on Promotion of Information and Communications Network Utilization and Data Protection of 2000

Spain. Organic Law 15/1999 of December 13 on the Protection of Personal Data

Switzerland. Federal Law on Data Protection of 1992

Sweden. Personal Data Protection Act (1998: 204), October 24, 1998

Taiwan. Computer Processed Personal Data Protection Law (public institution applicability only)

Thailand. Official Information Act, B.E. 2540 (1997) (for state agencies)

United Kingdom. UK Data Protection Act 1998; Privacy and Electronic Communications (EC Directive) Regulations 2003

Vietnam. Law on Electronic Transactions 2008


1. Information Shield, “United States Privacy Laws,” (accessed October 18, 2013).

2. Information Shield, “International Privacy Laws,” (accessed February 1, 2014).

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.