A practical guide to understanding whether the law applies to your organisation, what it requires, the key terms you need to know, who should be involved, and where to start.
At its simplest, personal data protection is about how organisations handle information about people. Organisations need a good reason to collect and use personal data, they need to be clear about what they are doing with it, they need to protect it, and they need to respect people's rights.
That is the core idea. The differences between countries are mostly about who is covered, what organisations must do, what rights people have, who enforces the rules, and what happens when those rules are broken.
Two things surprise people most. First, these laws apply to ordinary organisations, not just tech companies: a clinic with patient records, a school with parent contacts, a shop with a mailing list, or an employer with staff records. Second, these regulations can apply across borders. An organisation may have to follow another country's regulations even when it is based somewhere else, depending on who it serves, what it does with personal data, and where those people are located.
If any of these are true, at least one data protection law already covers what you do.
You keep names, emails, phone numbers or addresses: for customers, staff, job applicants, donors, patients, or students.
You have customers, users or employees in another country: that country's law may reach you even if you have no office there.
You use analytics, advertising, email marketing or a CRM: these collect and share personal data by design.
You handle sensitive information: health, biometrics, financial details, religion, political views, or anything about children.
Someone else processes data for you: a payroll provider, cloud host, or agency. Their handling is still your responsibility.
The vocabulary that makes every country page, contract, and regulator letter readable.
Privacy work is a team work. These are the people involved and when to bring them in.
Your engineers, analysts, or IT provider are the only people who truly know where personal data lives, who can reach it, and what your tools quietly collect. No privacy programme survives without them.
One named person responsible for privacy e.g a Data Protection Officer where the law requires it, otherwise simply whoever will answer for it. Many countries mandate the role above a size or risk threshold.
Every tool that touches customer data needs a written agreement covering what they may do with it and where it goes. Ask before adopting, not after.
For binding advice, cross-border contracts, filings, and audits. Some countries license specific firms for this e.g Nigeria's DPCOs file compliance audits on your behalf, for instance.
Not only an enforcer. Supervisory authorities publish guidance, run registration portals, and answer questions. You will also contact them to report a breach. Each country page links yours directly.
You do not need a compliance department. These steps are ordered so the cheapest, highest-value work comes first.
Look up the country where your customers, staff or users are. Note the regulator, the breach deadline, and whether you must register. Open the country index →
A single spreadsheet: what personal data you hold, why you have it, where it lives, who can see it, and who you share it with. This is the seed of a RoPA and makes every later step easier.
Even where the law does not demand a DPO, pick a person. Privacy that belongs to everyone belongs to no one.
Say what you collect, why, who you share it with, how long you keep it, what rights people have, and how to contact you. Write it for a customer, not a court.
Old exports, abandoned spreadsheets, shared logins. Reduce who can reach personal data to those who need it, and set retention periods so data expires on purpose.
One page: who is told first, who decides whether it is reportable, who contacts the regulator, and the deadline. Deciding this calmly in advance is worth more than any policy document.
Vendor agreements, transfer mechanisms such as SCCs, DPIAs for high-risk projects, registration and audits where required. By now you will know which of these you actually need.
Now that you know the shape of it, let's get specific.
Start with the privacy law that applies to you. See the key requirements, regulator, deadlines, penalties, and links to official sources.
Browse all countries → Operating in severalCompare up to three countries side by side to see where their privacy requirements are different.
Open Compare → Ready to buildFind free and open-source tools, templates, and reference materials to help you put privacy requirements into practice.
Go to Resources →Official sources, guidance, and communities for privacy professionals.