Tree of Knowledge Wiki

Privacy law refers to the laws that deal with the regulation, storing, and using of personally identifiable information, personal healthcare information, and financial information of individuals, which can be collected by governments, public or private organisations, or other individuals. It also applies in the commercial sector to things like trade secrets and the liability that directors, officers, and employees have when handing sensitive information.

Privacy laws are considered within the context of an individual's privacy rights or within reasonable expectation of privacy.

Classification of privacy laws

Privacy laws can be broadly classified into:

  • General privacy laws that have an overall bearing on the personal information of individuals and affect the policies that govern many different areas of information.
    • Trespass
    • Negligence
    • Fiduciary Duty
    • Contract
    • Unfair and Deceptive Trade Practices
  • Specific privacy laws that are designed to regulate specific types of information. Some examples include:
    • Communication privacy laws
    • Financial privacy laws
    • Health privacy laws
    • Information privacy laws
    • Online privacy laws
    • Privacy in one's home

International legal standards on privacy

Asia-Pacific Economic Cooperation (APEC)

APEC created a voluntary Privacy Framework that was adopted by all 21 member economies in 2004 in an attempt to improve general information privacy and the cross-border transfer of information. The Framework consists of nine Privacy Principles that act as minimum standards for privacy protection: Preventing harm, Notice, Collection limitation, Use of personal information, Choice, Integrity of personal information, Security safeguards, Access and correction, and Accountability.

In 2011, APEC implemented the APEC Cross Border Privacy Rules System with the goal of balancing "the flow of information and data across borders ... essential to trust and confidence in the online marketplace." The four agreed-upon rules of the System are based upon the APEC Privacy Framework and include self-assessment, compliance review, recognition/acceptance, and dispute resolution and enforcement.

Council of Europe

Article 8 of the European Convention on Human Rights, which was drafted and adopted by the Council of Europe in 1950 and currently covers the whole European continent except for Belarus and Kosovo, protects the right to respect for private life: "Everyone has the right to respect for his private and family life, his home and his correspondence." Through the huge case-law of the European Court of Human Rights in Strasbourg, privacy has been defined and its protection has been established as a positive right of everyone.

The Council of Europe also adopted Convention for the protection of individuals with regard to automatic processing of personal data in 1981 and addressed privacy protection in regards to the Internet in 1998 when it published "Draft Guidelines for the protection of individuals with regard to the collection and processing of personal data on the information highway, which may be incorporated in or annexed to Code of Conduct." The Council developed these guidelines in conjunction with the European Commission, and they were adopted in 1999.

European Union (EU)

The 1995 Data Protection Directive (officially Directive 95/46/EC) recognized the authority of National data protection authorities and required that all Member States adhere to universal privacy protection standards. Member States must adopt strict privacy laws that are no more relaxed than the framework provided by the directive. Additionally, the Directive outlines that non-EU countries must adopt privacy legislation of equal restriction in order to be allowed to exchange personal data with EU countries. Furthermore, companies in non-EU countries must also adopt privacy standards of at least equal restriction as provided in the Directive in order to do business with companies located in EU countries. Thus, the Directive has also influenced the development of privacy legislation in non-European countries. The proposed ePrivacy Regulation, which would replace the Privacy and Electronic Communications Directive 2002, also contributes to EU privacy regulations.

The General Data Protection Regulation has replaced the Data Protection Directive of 1995 when it came to effect on 25 May 2018. A notable contribution that has come from the General Data Protection Regulation is its recognition of a "right to be forgotten", which requires any group that collects data on individuals to delete the data related to an individual upon that individual's request. The Regulation was influenced by the aforementioned European Convention on Human Rights.

Organization for Economic Co-operation and Development (OECD)

In 1980, the OECD adopted the voluntary OECD Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data in response to growing concerns about information privacy and data protection in an increasingly technological and connected world. The OECD Guidelines helped establish an international standard for privacy legislation by defining the term "personal data" and outlining fair information practice principles (FIPPs) that other countries have adopted in their national privacy legislation.

In 2007, the OECD adopted the Recommendation on Cross-border Co-operation in the Enforcement of Laws Protecting Privacy. This framework is based on the OECD Guidelines and includes two cooperation based model forms to encourage the enforcement of privacy laws among member states. The Recommendation is also notable for coining the term "Privacy Enforcement Authority."

United Nations (UN)

Article 17 of the International Covenant on Civil and Political Rights of the United Nations in 1966 also protects privacy: "No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."

On December 18, 2013, the United Nations General Assembly adopted resolution 68/167 on the right to privacy in the digital age. The resolution makes reference to the Universal Declaration of Human Rights and reaffirms the fundamental and protected human right of privacy.

The Principles on Personal Data Protection and Privacy for the United Nations System were declared on 11 October 2018.

Privacy laws by country

For a comprehensive global summary of data privacy laws (2017), click here to access Greenleaf's article documenting the change of privacy regulations throughout the international landscape.


Main articles: Privacy in Australian law

The current state of privacy law in Australia includes Federal and state information privacy legislation, some sector-specific privacy legislation at state level, regulation of the media and some criminal sanctions. The current position concerning civil causes of action for invasion of privacy is unclear: some courts have indicated that a tort of invasion of privacy may exist in Australia. However this has not been upheld by the higher courts, which have been content to develop the equitable doctrine of Breach of Confidence to protect privacy, following the example set by the UK. In 2008, the Australian Law Reform Commission recommended the enactment of a statutory cause of action for invasion of privacy.


The Bahamas has an official data protection law that protects the personal information of its citizens in both the private and public sector: Data Protection Act 2003 (the Bahamas Law). The Bahamas Law appoints a data protection commissioner to the Office of Data Protection to ensure that data protection is being held. Even though there is legislation enforced in the Bahamas through the Data Protection Act 2003, the act lacks many enforcements since a data protection officer doesn't need to be in office nor does any group or organization need to notify the Office of Data Protection when a hacker has breached privacy law. Also, there are no requirements for registering databases or restricting data flow across national borders. Therefore, the legislation does not meet European Union standards, which was the goal of creating the law in the first place. 

The Bahamas is also a member of CARICOM, the Caribbean Community.


Belize is currently part of the minority of countries that do not have any official data privacy laws. However, the Freedom of Information Act (2000) currently protects the personal information of the citizens of Belize, but there is no current documentation that distinguishes if this act includes electronic data.

As a consequence of the lack of official data privacy laws, there was a breach of personal data in 2009 when an employee's laptop from Belize's Vital Statistics Unit was stolen, containing birth certification information for all citizens residing in Belize. Even though the robbery was not intentionally targeting the laptop - the robber did not predict the severity of the theft - Belize was put in a vulnerable position which could have been avoided if regulations were in order.


A Brazilian citizen's privacy is protected by the country's constitution, which states:

The intimacy, private life, honor and image of the people are inviolable, with assured right to indenization by material or moral damage resulting from its violation

On 14 August 2018, Brazil enacted a full-fledged data protection bill. The bill has 65 articles and has many similarities to the GDPR. The first translation into English of the new data protection law was published by Ronaldo Lemos, a Brazilian lawyer specialized in technology, on that same date. There is a newer version.


Main articles: Canadian privacy law

In Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs the collection, use, and disclosure of personal information in connection with commercial activities and personal information about employees of federal works, undertakings and businesses. It generally does not apply to non-commercial organizations or provincial governments. Personal information collected, used and disclosed by the federal government and many crown corporations is governed by the Privacy Act. Many provinces have enacted similar provincial legislation such as the Ontario Freedom of Information and Protection of Privacy Act which applies to public bodies in that province.

There remains some debate whether there exists a common law tort for breach of privacy. There have been a number of cases identifying a common law right to privacy but the requirements have not been articulated.

In Eastmond v. Canadian Pacific Railway & Privacy Commissioner of Canada Canada's Supreme Court found that CP could collect Eastmond's personal information without his knowledge or consent because it benefited from the exemption in paragraph 7(1)(b) of PIPEDA, which provides that personal information can be collected without consent if "it is reasonable to expect that the collection with the knowledge or consent of the individual would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement".


Computer Processed Personal Information Protection Act was enacted in 1995 in order to protect personal information processed by computers. The general provision specified the purpose of the law, defined crucial terms, prohibited individuals from waiving certain rights.


An archipelago located in the Pacific, the country of Fiji was founded on the tenth of October 1970. In its constitution, the people inhabiting the land are granted the right to privacy. The exact workings from the constitution is the following: "Every person has the right to personal privacy, which includes the right to — (a) confidentiality of their personal information; (b) confidentiality of their communications; and (c) respect for their private and family life". But in this very same constitution, it is expressed that it is possible "to the extent that it is necessary" for a law to be passed that limits or impacts the execution of the right to privacy law. Another privacy related law can be seen in section 54 of the Telecommunications Promulgation passed in 2008, which states that "any service provider supplying telecommunications to consumers must keep information about consumers confidential". Billing information and call information are no exceptions. The only exception to this rule is for the purpose of bringing to light "fraud or bad debt". Under this law, even with the consent of the customer, the disclosure of information is not permitted.

Other Privacy laws that have been adopted by this country are those that are meant to protect the collected information, cookies and other privacy-related matter of tourist. This is in regards to (but not limited to) information collected during bookings, the use of one technology of another that belongs to said company or through the use of a service of the company, or when making payments. Additionally, as a member of the United Nations, the Fiji is bound by the universal declaration of Human Rights which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


France adopted a data privacy law in 1978. It applies to public and private organizations and forbids gathering sensitive data about physical persons (sexuality, ethnic, political or religious opinions ...). The law is administered by the Commission nationale de l'informatique et des libertés (CNIL), a dedicated national administration. Like in Germany data violations are considered criminal offenses (Art. 84 GPR with Code Pénal, Section 1, Chapitre VI, Art. 226ff.).


Germany is known to be one of the first countries (in 1970) with the strictest and most detailed data privacy laws in the world. The citizens' right to protection is stated in the Constitution of Germany, in Art. 2 para. 1, and Art. 1 para. 1. The citizens' data of Germany is mainly protected under the Federal Data Protection Act (1977) from corporations, which has been amended the most recently in 2009. This act specifically targets all businesses that collect information for its use. The major regulation protects the data within the private and personal sector, and as a member of the European Union (EU), Germany has additionally ratified its act, convention, and additional protocol with the EU according to the EU Data Protection Directive 95/46 EC.

In Germany, there are two kinds of restrictions on a transfer of personal data. Since Germany is part of the EU Member States, the transfer of personal data of its citizens to a nation outside the EEA is always subject to a decent level of data protection in the offshore country. Secondly, according to German data policy rules, any transfer of personal data outside the EEA symbolizes a connection to a third party which requires a reason. That reason may be for emergency reasons and a provision must be met with consent by the receiver and the subject of the data. Keep in mind that in Germany, data transfers within a group of companies are subject to same treatment as transfer to third-parties if the location is outside the EEA.

Specifically the Federal Data Protection Commission is in charge of regulating the entirety of the enforcement of data privacy regulations for Germany. In addition, Germany is part of the Organisation for Economic Cooperation and Development (OECD). The Federal Data Protection Commission of Ireland is a member of the International Conference of Data Protection and Privacy Commissioners, European Data Protection Authorities, the EU Article 29 Working Party, and the Global Privacy Enforcement Network.

Regarding the protection of children, Germany is potentially the first nation that has played an active role in banning the share of data within toys connected to Wifi and the Internet, like for instance, "My Friend Cayla". The group in charge of protecting the data of children is the Federal Network Agency (Bundesnetzagentur). 

Like in France data violations are considered offenses (Art. 84 GPR with § 42 BDSG).


During the military dictatorship era the 57 AK law prohibited taking photos of people without their permission but the law has since been superseded. The 2472/1997 law protects personal data of citizens but consent for taking photos of people is not required as long as they aren't used commercially or are used only for personal archiving ("οικιακή χρήση" / "home use"), for publication in editorial, educational, cultural, scientific or news publications, and for fine art purposes (e.g. street photography which has been uphold as legal by the courts whether done by professional or amateur photographers). However, photographing people or collecting their personal data for commercial (advertising) purposes requires their consent. The law gives photographers the right to commercially use photos of people who have not consented to the use of the images in which they appear if the depicted people have either been paid for the photo session as models (so there is no separation between editorial and commercial models in Greek law) or they have paid the photographer for obtaining the photo (this, for example, gives the right to wedding photographers to advertise their work using their photos of newly-wed couples they photographed in a professional capacity). In Greece the right to take photographs and publish them or sell licensing rights over them as fine art or editorial content is protected by the Constitution of Greece (Article 14 and other articles) and free speech laws as well as by case law and legal cases. Photographing the police or children and publishing the photographs in a non-commercial capacity is also legal.

Hong Kong

In Hong Kong, the law governing the protection of personal data is principally found in the Personal Data (Privacy) Ordinance (Cap. 486) which came into force on 20 December 1996. Various amendments were made to enhance the protection of personal data privacy of individuals through the Personal Data (Privacy) (Amendment) Ordinance 2012. Examples of personal data protected include names, phone numbers, addresses, identity card numbers, photos, medical records and employment records. As Hong Kong remains a common law jurisdiction, judicial cases are also a source of privacy law. The power of enforcement is vested with the Privacy Commissioner (the "Commissioner") for Personal Data. Non-compliance with data protection principles set out in the ordinances does not constitute a criminal offense directly. The Commissioner may serve an enforcement notice to direct the data user to remedy the contravention and/or instigate the prosecution action. Contravention of an enforcement notice may result in a fine and imprisonment.


The Right to Privacy is a fundamental right and an intrinsic part of Article 21 that protects life and liberty of the citizens and as a part of the freedoms guaranteed by Part III of the Constitution. In June 2011, India passed subordinate legislation that included various new rules that apply to companies and consumers. A key aspect of the new rules required that any organization that processes personal information must obtain written consent from the data subjects before undertaking certain activities. However, application and enforcement of the rules is still uncertain. The Aadhaar Card privacy issue became controversial when the case reached the Supreme Court. The hearing in the Aadhaar case went on for 38 days across 4 months, making it the second longest Supreme Court hearing after the landmark Kesavananda Bharati v. State of Kerala.

On 24 August 2017, a nine-judge bench of the Supreme Court in Justice K. S. Puttaswamy (Retd.) and Anr. vs Union Of India And Ors. unanimously held that the right to privacy is an intrinsic part of right to life and personal liberty under Article 21 of the Constitution.

Previously, the Information Technology (Amendment) Act, 2008 made changes to the Information Technology Act, 2000 and added the following two sections relating to Privacy:

  • Section 43A, which deals with implementation of reasonable security practices for sensitive personal data or information and provides for the compensation of the person affected by wrongful loss or wrongful gain.
  • Section 72A, which provides for imprisonment for a period up to three years and/or a fine up to Rs. 500,000 for a person who causes wrongful loss or wrongful gain by disclosing personal information of another person while providing services under the terms of lawful contract. A constitutional bench of the Supreme Court declared 'Privacy' as a fundamental right on 24 August 2017.


The island of Ireland is under the Data Protection Act 1988 and amended by the Data Protection Act 2003 along with the EU Data Protection Directive 95/46 EC, which regulates the utilization of personal data. Data Protection Act 1988 along with 2003 is known as the DPA and protects data within the private and personal sector. The DPA ensures that when data is transported, the location must be safe and in acknowledgement of the legislation to maintain data privacyWhen collecting and processing data, some of the requirements are listed below:

  • the subject of personal data must have given consent
  • the data is in the subject's interest
  • the reason for the processing of data is for a contract
  • the reason for the processing of data is the prevention of injury

Specifically the Data Protection Commissioner oversees the entirety of the enforcement of data privacy regulations for Ireland. All persons that collect and process data must register with the Data Protection Commissioner unless they are exempt (non-profit organizations etc.) and renew their registration annually.

Electronic Privacy Protection

Considering the protection of internet property and online data, the ePrivacy Regulations 2011 protects the communications and higher-advanced technical property and data such as social media and the telephone.

In relation to international data privacy law that Ireland is involved in, the British-Irish Agreement Act 1999 Section 51 extensively states the relationship between data security between the United Kingdom and Ireland.

In addition, Ireland is part of the Council of Europe and the Organisation for Economic Cooperation and Development.

The Data Protection Commissioner of Ireland is a member of the International Conference of Data Protection and Privacy Commissioners, European Data Protection Authorities, the EU Article 29 Working Party, Global Privacy Enforcement Network, and the British, Irish, and Islands Data Protection Authorities.

Ireland is also the main international location for social media platforms, specifically LinkedIn and Twitter, for data collection and control for any data processed outside the United States.


The Jamaican constitution grants its people the right to "respect for and protection of private and family life, and privacy of the home". Although the government grants its citizens the right to privacy, the protection of this right is not strong. But in regards to other privacy laws that has been adopted in the country of Jamaica, the closest one is the Private Security Regulation Authority Act. This act passed in the year 1992, established the Private Security Regulation Authority. This organization is tasked with the responsibility of regulating the private security business and ensuring that everyone working as a private security guard is trained and certified. The goal of this is to ensure a safer home, community, and businesses. One of the reasons as to why this law was passed is that as trained workers, the guards could ensure maximum Customer service and also with the education they received they would be equipped how best to deal with certain situations as well as avoid actions can that could be considered violations, such as invasion of privacy. Additionally, as a member of the United Nations, the Jamaica is bound by the Universal Declaration of Human Rights which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


The Act on the Protection of Personal Information was fully enacted in 2005 to protect the rights and interests of individuals while taking consideration of the usefulness of personal information. The law applies to business operators that hold the personal information of 5,000 or more individuals.


Kenya currently does not have a strong general privacy protection law for its constituents. But in chapter 4 — The Bill of Rights and in the second part which is titled "Rights and Fundamental Freedoms," of the consitiution privacy is allocated its own section. There we see that the Kenyan government express that all its people have the right to privacy, "... which includes the right not to have — (a) their person, home or property searched; (b) their possessions seized; (c) information relating to their family or private affairs unnecessarily required or revealed, or (d) the privacy of their communications infringed". Although Kenya grants its people the right to privacy, there seems to be no existing document that protects these specific privacy laws. Regarding privacy laws relating to data privacy, like many African countries as expressed by Alex Boniface Makulilo, Kenya's privacy laws are far from the European 'adequacy' standard".

As of today, Kenya does have laws that focus on specific sectors. The following are the sectors: communication and information. The law pertaining to this is called the Kenya Information and Communication Act. This Act makes it illegal for any licensed telecommunication operators to disclose or intercept information that is able to get access through the customer's use of the service. This law also grants privacy protection in the course of making use of the service provided by said company. And if the information of the customer is going to be provided to any third party it is mandatory that the customer is made aware of such an exchange and that some form of agreement is reached, even if the person is a family member. This act also goes as far as protecting data for Kenyans especially for the use of fraud and other ill manners. Additionally, as a member of the United Nations, Kenya is bound by the universal declaration of Human Rights which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


After their independence from Great Britain in 1957, Malaysia's existing legal system was based primarily on English common law. The following common law torts are related to personal information privacy and continue to play a role in Malaysia's legal system: breach of confidence, defamation, malicious falsehood, and negligence. In recent years, however, the Court of Appeal in Malaysia has referred less to English common law and instead looked more toward other nations with similar colonial histories and whose written constitutions are more like the Malaysian Constitution. Unlike the courts in these other nations, such as India's Supreme Court, the Malaysian Court of Appeal has not yet recognized a constitutionally protected right to privacy.

In June 2010, the Malaysian Parliament passed the Personal Data Protection Act 2010, and it came into effect in 2013. It outlines seven Personal Data Protection Principles that entities operating in Malaysia must adhere to: the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle, and the Access Principle. The Act defines personal data as "'information in respect of commercial transactions that relates directly or indirectly to the data subject, who is identified or identifiable from that information or from that and other information."

A notable contribution to general privacy law is the Act's distinction between personal data and sensitive personal data, which entails different protections. Personal data includes "information in respect of commercial transactions ... that relates directly or indirectly to a data subject" while sensitive personal data includes any "personal data consisting of information as to the physical or mental health or condition of a data subject, his political opinions, his religious beliefs or other beliefs of a similar nature." Although the Act does not apply to information processed outside the country, it does restrict cross-border transfers of data from Malaysia outwards. Additionally, the Act offers individuals the "right to access and correct the personal data held by data users", "the right to withdraw consent to the processing of personal data", and "the right to prevent data users from processing personal data for the purpose of direct marketing." Punishment for violating the Personal Data Protection Act can include fines or even imprisonment.

Other common law and business sector-specific laws that exist in Malaysia to indirectly protect confidential information include:


On 5 July 2010, Mexico enacted a new privacy package focused on treatment of personal data by private entities. The key elements included were:

  • Requirement of all private entities who gather personal data to publish their privacy policy in accordance to the law.
  • Set fines for up to $16,000,000 MXN in case of violation of the law.
  • Set prison penalties to serious violations.

New Zealand

In New Zealand, the Privacy Act 1993 sets out principles in relation to the collection, use, disclosure, security and access to personal information.

The introduction into the New Zealand common law of a tort covering invasion of personal privacy at least by public disclosure of private facts was at issue in Hosking v Runting and was accepted by the Court of Appeal. In Rogers v TVNZ Ltd the Supreme Court indicated it had some misgivings with how the tort was introduced, but chose not to interfere with it at that stage.

Complaints about privacy are considered by the Privacy Commissioner


Federal Republic of Nigeria's constitution offers its constituents the right to privacy as well as privacy protection. The following can be found in the constitution pertaining to this: "The privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is hereby guaranteed and protected". Additionally, as a member of the United Nations, Nigeria is bound by the universal declaration of Human Rights which states in article twelve "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks". Nigeria is one of the few African countries that is building on the privacy laws. This is evident in the fact that Nine years later in the year 2008, the Cybersecurity and Information Protection Agency Bill was passed. This bill is responsible for the creation of the Cybersecurity and Information Protection Agency. This agency is tasked with the job of preventing cyberattacks and regulating the Nigerian information technology industry. Additional laws have been passed that are meant to prevent the disclosure of information without permission and the intercepting of some form of transaction with or without evil intent.


In Article III, Section 3, paragraph 1 of the 1987 Constitution of the Philippines lets its audience know that "The privacy of communication and correspondence shall be inviolable except upon lawful order of the court, or when public safety or order requires otherwise as prescribed by law". Not only does this country grant the Filipinos the right to privacy, but it also protects its people's right to privacy by attaching consequences to the violation of it thereof. In the year 2012, the Philippines passed the Republic Act No. 10173, also known as the "Data Privacy Act of 2012". This act extended privacy regulations and laws to apply to more than just individual industries. This act also offered protection of data belonging to the people regardless of where it is stored, be it in private spheres or not. In that very same year, the cybercrime prevention law was passed. This law was "intended to protect and safeguard the integrity of computer and communications systems" and prevent them from being misused. Not only does the Philippines have these laws, but it has also set aside agents that are tasked with regulating these privacy rules and due ensure the punishment of the violators. Additionally, with the constitution, previous laws that have been passed but that are in violation of the laws above have been said to be void and nullified. Another way this country has shown their dedication in executing this law is extending it to the government sphere as well. Additionally, as a member of the United Nations, the Philippines is bound by the Universal Declaration of Human Rights which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


Main articles: Data protection (privacy) laws in Russia

Applicable legislation:

  1. Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, signed and ratified by the Russian Federation on December 19.2005;
  2. the Law of the Russian Federation "On Personal Data" as of 27 July 2006 No. 152-FZ, regulating the processing of personal data by means of automation equipment. It is the operator who is required to comply with that Act.

As a general rule, consent of the individual is required for processing, i.e. obtaining, organizing, accumulating, holding, adjusting (updating, modifying), using, disclosing (including transfer), impersonating, blocking or destroying of his personal data. This rule doesn't apply where such processing is necessary for performance of the contract, to which an individual is a party.


Singapore, like other Commonwealth jurisdictions, relies primarily on common law, and the law of confidence is employed for privacy protection cases. For example, privacy can be protected indirectly through various common law torts: defamation, trespass, nuisance, negligence, and breach of confidence. In February 2002, however, the Singaporean government decided that the common law approach was inadequate for their emerging globalized technological economy. Thus, the National Internet Advisory Committee published the Model Data Protection Code for the Private Sector, which set standards for personal data protection and was influenced by the EU Data Protection Directive and the OECD Guidelines on the Protection of Privacy. In the private sector, businesses can still choose to adopt the Model Code, but in 2005 Parliament decided that Singapore needed a more comprehensive legislative privacy framework.

In January 2013, Singapore's Personal Data Protection Act 2012 came into effect in three separate but related phases. The phases continued through July 2014 and dealt with the creation of the Personal Data Protection Commission, the national Do Not Call Registry, and general data protection Rules. The Act's general purpose "is to govern the collection, use and disclosure of personal data by organisations" while acknowledging the individual's right to control their personal data and the organizations' legal needs to collect this data. It imposes eight obligations on those organizations that use personal data: consent, purpose limitation, notification, access, correction, accuracy, protection/security, and retention. The Act prohibits transfer of personal data to countries with privacy protection standards that are lower than those outlined in the general data protection rules. The Personal Data Protection Commission is responsible for enforcing the Act, which is based primarily on a complaints-based system. The punishments for violating the Act can include being ordered by the Commission to stop collecting and using personal data, to destroy the data, or to pay a penalty of up to $1 million.

Singapore has also passed various sector-specific statutes that more indirectly deal with privacy and personal information, including:

There are also more specific acts for electronically stored information:

  • Spam Control Act 2007
  • Electronic Transactions Act
  • National Computer Board Act
  • Computer Misuse Act

South Africa

The Constitution of South Africa guarantees the most general right to privacy for all its citizens. This provides the main protection for personal data privacy so far.

The Protection of Personal Information Act 2013 (POPI) was signed into act, focusing on data privacy and is inspired by other foreign national treaties like the United Kingdom. Minimum requirements are presented in POPI for the act of processing personal data, like the fact that the data subject must provide consent and that the data will be beneficial, and POPI will be harsher when related to cross-border international data transfers, specifically with personal information. However, POPI won't be in full effective until an estimated date of 2018 as it is still being deliberated by the National Council of Provinces.

The recording of conversations over phone and internet is not allowed without the permission of both parties with the Regulation of Interception of Communications and Provision of Communications Related Act (2002).

In addition, South Africa is part of the Southern African Development Community and the African Union.


See also: Internet privacy#Internet privacy in Sweden

The Data Act is the world's first national data protection law and was enacted in Sweden on 11 May 1973. The law was then superseded on 24 October 1998 by the Personal Data Act (Sw. Personuppgiftslagen) that implemented the 1995 EU Data Protection Directive.


The main legislation over personal data privacy for the personal and private sector in Switzerland is the Swiss Federal Protection Act, specifically the Data Protection Act, a specific section under the Swiss Federal Protection Act. The Data Protection Act has been enacted since 1992 and is in charge of measuring the consent of sharing of personal data, along with other legislation like the Telecommunication Act and the Unfair Competition Act. The Act generally guides on how to collect, process, store, data, use, disclose, and destruct data. The Data Inspection Board is in charge of overseeing data breaches and privacy enforcement.

Personal data must be protected against illegal use by "being processed in good faith and must be proportionate". Also, the reason for the transfer of personal data must be known by the time of data transfer. Data not associated with people (not personal data) is not protected by the Data Protection Act.

In the case of data transfer to unsafe data protection countries, these are the major regulations required by the Data Protection Act:

  • Need of direct channels for data transfer
  • Individual case must have consent from receivers of data
  • Disclosure is accessible to public

Switzerland is a white-listed country, meaning that it is a nation that has proper levels of data protection under the surveillance by the European Commission (EU Commission). Switzerland is not under the EU Data Protection Directive 95/46 EC. However, the data protection regulations are sufficient enough under European Union (EU) regulations without being a member of the EU.

In addition, Switzerland is part of the Council of Europe and the Organisation for Economic Cooperation and Development.

The Data Inspection Board of Switzerland is a member of the International Conference of Data Protection and Privacy Commissioners, European Data Protection Authorities, the EU Article 29 Working Party, and the Nordic Data Protection Authorities.


The right to privacy is not explicitly mentioned in the Republic of China Constitution, but it can be protected indirectly through judicial interpretation. For example, article 12 of the Constitution states "the people shall have freedom of confidentiality of correspondence" while article 10 states "the people shall have freedom of residence and of change of residence." Along with several other articles that assert the Constitution's protection of freedoms and rights of the people, the Grand Justices are able to decide how privacy protection fits into the legal system. The Justices first made reference to privacy being a protected right in the 1992 "Interpretation of Council of Grand Justices No. 293 on Disputes Concerning Debtors' Rights," but it was not directly or explicitly declared to be a right.

In 1995, Taiwan passed the Computer-Processed Personal Data Protection Act which was influenced by the OECD Guidelines and enforced by each separate Ministry depending on their industry sector responsibility. It only protected personal information managed by government agencies and certain industries. In 2010, Taiwan enacted the Personal Data Protection Act that laid out more comprehensive guidelines for the public and private sectors and was still enforced by individual Ministries. In the 2010 Act, personal data is protected and defined as any "data which is sufficient to, directly or indirectly, identify that person", and includes data such as name, date of birth, fingerprints, occupation, medical records, and financial status, among many others.

A few other administrative laws also deal with communication-specific personal privacy protection:

  • Telecommunications Act
  • Communications Protection and Surveillance Act

Additionally, chapter 28 of the Criminal Code outlines punishments for privacy violations in article 315, sections 315-1 and 315-2. The sections primarily address issues of search and seizure and criminal punishment for wrongful invasion of privacy.

Finally, articles 18(I),184(I), and 195(I) of the Taiwanese Civil Code address the "personality right" to privacy and the right to compensation when one injures the "rights" of another, such as when someone uses another's name illegally.


Thailand's unique history of being an authoritarian buffer state during the Cold War and being under the constant threat of a coup d'état means that privacy laws have so far been limited in order to preserve national security and public safety. Thailand uses bureaucratic surveillance to maintain national security and public safety, which explains the 1991 Civil Registration Act that was passed to protect personal data in computerized record-keeping and data-processing done by the government.

The legislature passed the Official Information Act 1997 to provide basic data protection by limiting personal data collection and retention in the public sector. It defines personal information in a national context in relation to state agencies. Two communication technology related laws, the Electronic Transactions Act 2001 and the Computer Crime Act 2007, provide some data privacy protection and enforcement mechanisms. Nevertheless, Thailand still lacks legislation that explicitly addresses privacy security.

Thus, with the need for a more general and all-encompassing data protection law, the legislature proposed the Personal Data Protection Bill in 2013, which is heavily influenced by the OECD Guidelines and the EU Directive. The draft law is still under evaluation and its enactment date is not yet finalized.

United Kingdom

Main articles: Privacy in English law

As a member of the European Convention on Human Rights, the United Kingdom adheres to Article 8 of the European Convention on Human Rights, which guarantees a "right to respect for privacy and family life" from state parties, subject to restrictions as prescribed by law and necessary in a democratic society towards a legitimate aim.

However, there is no independent tort law doctrine which recognises a right to privacy. This has been confirmed on a number of occasions.

United States

Main articles: Privacy laws of the United States

The right to privacy is not explicitly stated anywhere in the Bill of Rights. The idea of a right to privacy was first addressed within a legal context in the United States. Louis Brandeis (later a Supreme Court justice) and another young lawyer, Samuel D. Warren, published an article called "The Right to Privacy" in the Harvard Law Review in 1890 arguing that the United States Constitution and common law allowed for the deduction of a general "right to privacy".

Their project was never entirely successful, and the renowned tort expert and Dean of the College of Law at University of California, Berkeley, William Lloyd Prosser argued in 1960 that "privacy" was composed of four separate torts, the only unifying element of which was a (vague) "right to be left alone". The four torts were:

  • Appropriating the plaintiff's identity for the defendant's benefit
  • Placing the plaintiff in a false light in the public eye
  • Publicly disclosing private facts about the plaintiff
  • Unreasonably intruding upon the seclusion or solitude of the plaintiff

One of the central privacy policies concerning minors is the Children's Online Privacy Protection Act (COPPA), which requires children under the age of thirteen to gain parental consent before putting any personal information online.

For additional information on Privacy laws in the United States, see:

Recently, a handful of lists and databases are emerging to help risk managers research US State and Federal laws that define liability. They include:

  • Perkins Coie Security Breach Notification Chart: A set of articles (one per state) that define data breach notification requirements among US states.
  • NCSL Security Breach Notification Laws: A list of US state statutes that define data breach notification requirements.
  • ts jurisdiction: A commercial cybersecurity research platform with coverage of 380+ US State & Federal laws that impact cybersecurity before and after a breach. ts jurisdiction also maps to the NIST Cybersecurity Framework.


Though the right to privacy exists in several regulations, the most effective privacy protections come in the form of constitutional articles of Uzbekistan. Varying aspects of the right to privacy are protected in different ways by different situations.


Vietnam, lacking a general data protection law, relies on Civil Code regulations relating to personal data protection. Specifically, the Code "protects information relating to the private life of a person." The 2006 Law on Information Technology protects personal information, such as name, profession, phone number, and email address, and declares that organizations may only use this information for a "proper purpose". The legislation, however, does not define what qualifies as proper. The 2005 Law on Electronic Transactions protects personal information during electronic transactions by prohibiting organizations and individuals from disclosing "part or all of information related to private and personal affairs ... without prior agreement." The 2010 Law on Protection of Consumers' Rights provides further protection for consumer information, but it does not define the scope of that information or create a data protection authority; additionally, it is only applicable in the private sector.

In 2015, the Vietnam legislature introduced the Law on Information Security, which ensures better information safety and protection online and in user's computer software. It took effect on 1 July 2016 and is Vietnam's first overarching data protection legislation.

Countries without official data privacy laws


  • Afghanistan
  • Algeria
  • Bahrain
  • Bangladesh
  • Belarus
  • Belize
  • Bolivia
  • Botswana
  • Burundi
  • Cambodia
  • Cameroon
  • Central African Republic
  • Comoros
  • Cuba
  • Djibouti
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Eritrea
  • Ethiopia
  • Fiji
  • Gambia
  • Guatemala
  • Guinea
  • Haiti
  • Iran
  • Iraq
  • Jordan
  • Kiribati
  • Kuwait
  • Lebanon
  • Liberia
  • Libya
  • Malawi
  • Maldives
  • Mongolia
  • Mozambique
  • Myanmar
  • Namibia
  • Nauru
  • Oman
  • Pakistan
  • Palau
  • Palestine
  • Panama
  • Papua New Guinea
  • Rwanda
  • Samoa
  • Saudi Arabia
  • Sierra Leone
  • Somalia
  • Sri Lanka
  • Sudan
  • Syria
  • Tajikistan
  • Timor-Leste
  • Togo
  • Tonga
  • Turkmenistan
  • Tuvalu
  • United Arab Emirates
  • Uzbekistan
  • Vanuatu
  • Vatican (Holy See)
  • Venezuela
  • Zambia


This page uses content that though originally imported from the Wikipedia article Privacy law might have been very heavily modified, perhaps even to the point of disagreeing completely with the original wikipedia article.
The list of authors can be seen in the page history. The text of Wikipedia is available under the Creative Commons Licence.