DIFC Data Protection Law, 2020
The Dubai International Financial Centre (DIFC) Data Protection Law No. 5 of 2020 replaced the previous 2007 law, aligning more closely with GDPR standards. It applies to all entities established in the DIFC and those processing personal data of DIFC data subjects. The law introduces enhanced rights for individuals including right to data portability, right […]
UK GDPR (UK General Data Protection Regulation, Post-Brexit)
Following Brexit, the UK incorporated GDPR into domestic law as the UK GDPR, maintaining largely the same provisions while allowing for future divergence. Effective from January 1, 2021, it works alongside the Data Protection Act 2018 to form the UK’s data protection framework. Key differences include the ICO as the sole supervisory authority, specific provisions […]
CPRA (California Privacy Rights Act, 2020)
The California Privacy Rights Act, approved by voters in November 2020 and effective from January 1, 2023, significantly expands and strengthens the CCPA. It creates new consumer rights including the right to correct inaccurate information, right to limit use of sensitive personal information, and extends the “look-back” period for data access requests to 12 months. […]
CCPA (California Consumer Privacy Act, 2018)
The California Consumer Privacy Act, effective from January 1, 2020, is a landmark US state privacy law granting California residents comprehensive rights over their personal information. It applies to for-profit businesses that collect California residents’ personal information, meet specific thresholds (annual revenues over $25 million, data of 50,000+ consumers, or 50%+ revenue from selling data), […]
EU AI Act (Artificial Intelligence Act – Proposed, 2021)
The EU AI Act is the world’s first comprehensive AI regulation, proposed in 2021 and expected to be fully implemented by 2026. It establishes a risk-based approach categorizing AI systems into four levels: unacceptable risk (banned), high-risk, limited risk, and minimal risk. High-risk AI systems, including those used in biometric identification, critical infrastructure, and employment, […]
GDPR (General Data Protection Regulation, 2016)
The General Data Protection Regulation is the European Union’s comprehensive data protection law that came into force on May 25, 2018. It establishes strict rules for how organizations collect, process, store, and transfer personal data of EU residents. Key provisions include requiring explicit consent for data processing, mandatory data breach notifications within 72 hours, right […]
Information Technology Act, 2000 – Amended 2008)
The IT Act is based on the United Nations Model Law on Electronic Commerce and contains provisions on data protection and privacy, including Section 43A which provides for compensation in case of negligence in protecting sensitive personal data, and Section 72A which provides criminal punishment for unauthorized disclosure of personal information. The Act forms the foundation […]
Digital Personal Data Protection Act, 2023
This official document outlines India’s Digital Personal Data Protection Act, 2023, a comprehensive law enacted to regulate the processing of digital personal data. The Act aims to balance individual data protection rights with the necessity of processing such data for lawful purposes. It defines key terms like Data Fiduciary and Data Principal, establishes the Data Protection Board of India to oversee compliance, and […]