Comparative Data Protection and Privacy Law

Introduction

Data protection law has become a defining arena of comparative law in the digital age, with every major jurisdiction adopting legislation addressing the collection, processing, and transfer of personal data. The European Union’s General Data Protection Regulation (GDPR, 2016/679, effective 2018) established a global benchmark, but the responses of other legal systems — from comprehensive omnibus legislation (Brazil, Japan, South Korea) to sectoral patchworks (United States) to state-controlled surveillance regimes (China, Russia) — reveal fundamental differences in constitutional values, regulatory philosophy, and the balance between privacy rights and other interests. This article compares data protection frameworks across seven jurisdictions.

The European Union: The GDPR Model

The GDPR is the most influential data protection instrument globally. Built on the EU Charter of Fundamental Rights (Art 7 — privacy, Art 8 — data protection), it establishes a comprehensive rights-based framework applicable to any organization processing the personal data of individuals in the EU, regardless of where the processor is established (Art 3 — broad territorial scope). Key principles include lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; and integrity and confidentiality (Art 5). Processing requires a lawful basis (Art 6): consent, contract, legal obligation, vital interests, public task, or legitimate interests.

Data subject rights include the right of access (Art 15), right to rectification (Art 16), right to erasure (the “right to be delisted”, Art 17, established in Google Spain v AEPD, 2014), right to restriction of processing (Art 18), right to data portability (Art 20), and right to object (Art 21). The right not to be subject to automated individual decision-making (Art 22) addresses algorithmic governance. The Regulation mandates data protection impact assessments (Art 35), data breach notification within 72 hours (Art 33), appointment of data protection officers (Art 37), and designation of independent supervisory authorities in each member state (Art 51). The one-stop-shop mechanism designates the lead authority for cross-border processing. Fines reach the higher of €20 million or 4% of global annual turnover (Art 83). The GDPR’s extraterritorial reach and severe penalties have driven global convergence, with over 120 countries adopting GDPR-style legislation.

Germany and France: National Implementation and Enforcement

Germany and France, as EU member states, implement the GDPR with supplementary national provisions. The German Federal Data Protection Act (BDSG, 2018) includes sector-specific provisions on employee data protection (§ 26 BDSG — strictly limited processing for employment purposes), video surveillance (§ 4 BDSG), and credit reporting. Germany maintains a decentralized enforcement structure with the Federal Commissioner for Data Protection and Freedom of Information (BfDI) and sixteen state data protection authorities (Landesdatenschutzbeauftragte). The Federal Constitutional Court’s “right to informational self-determination” (Volkszählungsurteil, 1983) provides constitutional grounding for data protection, treating it as an aspect of personal dignity (Art 1 GG) and free development of personality (Art 2 GG).

France’s data protection authority (CNIL — Commission Nationale de l’Informatique et des Libertés) is among the most active GDPR enforcement bodies, having imposed significant fines on Google (€50 million, 2019), Amazon (€35 million, 2023), and others. French law supplements the GDPR through the Loi Informatique et Libertés (1978, extensively amended 2018), addressing health data, biometric data, and data processing by public authorities. The French Conseil d’État has developed important jurisprudence on the balance between data protection and national security, particularly regarding intelligence surveillance.

The United Kingdom: Post-Brexit Divergence

The UK, following Brexit, adopted the UK GDPR (retained EU law with amendments) and the Data Protection Act 2018. The UK GDPR is substantially equivalent to the EU GDPR, with adjustments for domestic institutional structures. The Information Commissioner’s Office (ICO) enforces UK data protection law. The UK has obtained EU adequacy decisions under Art 45 GDPR, permitting continued free flow of personal data from the EU, subject to periodic review. The UK’s Data Protection and Digital Information Bill (2024) proposes amendments to reduce compliance burdens for UK organizations, including changes to the definition of personal data, the legitimate interests basis for processing, and cookie consent requirements, potentially creating divergence from the EU framework.

The United States: Sectoral Federalism

The United States has no comprehensive federal data protection statute. Instead, privacy law operates through a sectoral patchwork. The Health Insurance Portability and Accountability Act (HIPAA, 1996) governs protected health information. The Gramm-Leach-Bliley Act (GLBA, 1999) addresses financial privacy. The Children’s Online Privacy Protection Act (COPPA, 1998) protects children under 13. The Federal Trade Commission Act § 5 prohibits unfair or deceptive practices, providing the FTC with enforcement authority over privacy violations. Common law privacy torts (intrusion upon seclusion, public disclosure of private facts, false light, appropriation) provide limited private rights of action.

State legislation has filled the federal gap. The California Consumer Privacy Act (CCPA, 2018, effective 2020) as amended by the California Privacy Rights Act (CPRA, 2020) established the most comprehensive state-level framework, granting rights to know, delete, opt-out of sale/sharing, correct, and limit use of sensitive personal information. Virginia (VCDPA, 2021), Colorado (CPA, 2021), Connecticut (CTDPA, 2022), Utah (UCPA, 2022), and Texas (TDPSA, 2023) have enacted comprehensive privacy statutes. State laws are not pre-empted, creating compliance complexity for national businesses. The American Privacy Rights Act (APRA, 2024, introduced but not enacted) would establish federal baseline data protection with pre-emption of state laws.

Russia: Data Localization and Surveillance

Russia’s data protection framework combines elements of the European model with distinctive state surveillance and localization requirements. The Federal Law on Personal Data (No. 152-FZ, 2006, extensively amended) establishes consent-based processing, data subject rights (access, rectification, deletion), and accountability obligations, modelled on pre-GDPR European standards. Data localization requirements (2015 amendment) mandate that Russian citizens’ personal data be processed using databases located in Russia, enforced by Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology, and Mass Media).

The Yarovaya Laws (2016) require telecommunications operators and internet companies to store user communications metadata for three years and content for six months (extended to one year in 2018), and to provide decryption capability to security services. The Sovereign Internet Law (2019) mandates installation of technical means for centralized traffic management and deep packet inspection. These surveillance obligations operate alongside formal data protection rules, creating a dual system where privacy rights are granted in law but constrained by state security imperatives. Courts have been reluctant to enforce data subject rights against state interests.

China: The PIPL and State Control

China’s Personal Information Protection Law (PIPL, 2021, effective November 2021) established the country’s first comprehensive data protection framework, modelled on the GDPR but adapted to the socialist legal system and Party-state priorities. The PIPL adopts GDPR-like principles — lawfulness, transparency, data minimization — and grants data subject rights (right to know, right to consent withdrawal, right to deletion, right to portability). Processing requires consent (Art 14), contract necessity, legal obligation, or legitimate interests. Separate consent is required for sensitive personal information (Art 29), including biometric data, financial accounts, and location data.

The PIPL’s distinctive features include stringent cross-border data transfer restrictions (Art 38–43), requiring security assessment by the Cyberspace Administration of China (CAC) for transfers of important data or personal information of large volumes, and standard contractual clauses or certification for other transfers. The restrictions reflect concerns about national security and law enforcement access to Chinese data. The Data Security Law (DSL, 2021) categorizes data by importance to national security, empowering the state to designate “important data” and impose strict controls. The PIPL provides for severe penalties (up to 5% of annual turnover or RMB 50 million) and personal liability for responsible managers.

The PIPL operates within a legal environment where state surveillance is extensive and legally authorized. The National Intelligence Law (2017) and the Counter-Espionage Law (2023) authorize broad data collection by security agencies. The tension between formal privacy rights and state control — particularly through the CAC’s enforcement discretion, the social credit system’s data aggregation, and facial recognition surveillance — defines China’s dual approach to data protection.

Comparison and Convergence

The five models — comprehensive rights-based (EU GDPR), state-led enforcement with localization (Russia), formal rights with state surveillance (China), sectoral federalism (US), and GDPR-equivalent with limited adaptation (UK) — reflect fundamentally different constitutional traditions, political structures, and economic priorities. The GDPR has achieved significant convergence through its market power (Brussels effect), with over 120 countries adopting GDPR-style frameworks including Brazil (LGPD), Japan (APPI), South Korea (PIPA), India (DPDP Act 2023), and Thailand (PDPA). The US remains the principal outlier at the federal level, though state legislation is converging toward GDPR-like rights. Russia and China adopt formal protections while maintaining surveillance frameworks that undermine their practical effectiveness.

Key emerging issues include AI-specific data protection (training data lawfulness, automated decision-making), international data transfers after Privacy Shield invalidation (Schrems II, 2020), enforcement of data subject rights against technology companies, children’s data protection, workplace monitoring, biometric data regulation, and the framework for international data governance in an era of data nationalism and digital sovereignty.