By identifying key players, quantifying relative influence, and assessing the competitive landscape, FP Analytics breaks down complex foreign policy issues by mapping out spheres of influence and the risks and opportunities these topics present. LEARN MORE

Global Data Governance

Database of Policies

UPDATED: Sept. 15, 2021
PUBLISHED: Oct. 6, 2020

Foreign Policy Analytics’ (FPA’s) Global Data Governance Power Map details emerging trends in private companies’ and governments’ data collection practices. These trends include the proliferation of data privacy and data localization laws, governments’ expanding data collection practices, changes in global encryption laws, the rising use of AI for data collection, and the proliferation of international cybersecurity commitments. Throughout the Power Map series, laws and policies related to these trends are catalogued and graphically broken down for readers.

As a reference and navigable tool, all of the practices and regulations chronicled in the Power Map series have been consolidated in FPA’s Global Data Governance Database below. This database provides a comprehensive regional and country-level breakdown of global data governance practices in 138 countries worldwide. For easy navigation, this searchable database can be sorted by country or region. For a deeper dive into each global data governance practice chronicled below, see the corresponding Power Map section.

Filter by location:

Filter by data policies/technology:

Afghanistan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyberspace Security Strategy (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Information System Security Directorate (ISSD)

International Commitments
  • No Data

Albania

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Authority for Electronic Certification and Cyber Security (NAECCS)

International Commitments
  • Member of the Budapest Convention (2004)

Angola

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Law (PDPL) (2000)
Other Data Privacy Laws
  • Electronic Communications and Information Society Services Law (2011)
  • Protection of Information Systems and Networks Law (2017)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Argentina

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Law (PDPL) (2000)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National data protection authority
  • Registration requirement
  • Data localization provisions - Local Copy
  • Cybersecurity provisions
  • Enforcement through fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
  • Chinese tech
  • Japanese tech
Source:
  • Chinese tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Program for Critical Information Infrastructure and Cybersecurity

International Commitments
  • Member of the Budapest Convention (2018)

Armenia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Armenia 2020 National Security Strategy (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Program for Critical Information Infrastructure and Cybersecurity

International Commitments
  • Member of the Budapest Convention (2007)

Australia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Federal Privacy Act (1988)
Other Data Privacy Laws
  • Information Privacy Act (2009)
Active Legal Provisions
  • National Data Protection Authority
  • Breach Notification
  • Cybersecurity Provisions
  • Data Localization Provisions - Conditional Restrictions
  • Enforcement Through Fine

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial Recognition
  • Predictive Policing
  • Chinese Tech
  • U.S. Tech
  • Japanese Tech
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Australia’s Cybersecurity Strategy 2020 (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Australian Signals Directorate

International Commitments
  • Member of the Budapest Convention (since 2013)
  • UN GGE 2019/2021 member

Austria

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Datenschutzgesetz (2000)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Austrian Cyber Security Strategy (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Cyber Security Steering Group

International Commitments
  • Member of the Budapest Convention (2012)

Azerbaijan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Strategy of the Republic of Azerbaijan on Information Security and Cybersecurity for 2021-2025 (DRAFT)

National Cybersecurity Agency: Cyber Security Center

International Commitments
  • Member of the Budapest Convention (2010)

Bahrain

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law No. 30 of 2018 with respect to Personal Data Protection (PDPL) (2008/2020)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Facial Recognition
  • Predictive Policing
  • Chinese Tech
Source:
  • Chinese Tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Information & eGovernment Authority

International Commitments
  • No Data

Bangladesh

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart City
  • Facial Recognition
  • Predictive Policing
  • Chinese Tech
Source:
  • Chinese Tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

The National Cybersecurity Strategy of Bangladesh (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: No Data

International Commitments
  • No Data

Belarus

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law on Personal Data Protection (DRAFT)
Other Data Privacy Laws
  • Data Protection Law (2008)
  • Population Register Law (2008)
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • Import/export controls

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Belgium

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Security Strategy, Securing Cyberspace (2012)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Centre for Cybersecurity Belgium (CCB)

International Commitments
  • Member of the Budapest Convention (2012)

Belize

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy - Towards A Secure Cyberspace 2020-2023 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Central Information Technology Office & National Cyber Security Task Force

International Commitments
  • No Data

Benin

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Digital Code (2018)
Other Data Privacy Laws
  • LAW N° 2009-09 OF MAY 22, 2009 Dealing with the protection of Personally Identifiable Information (PII) in the Republic of Benin (2009)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Digital Security Strategy (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Digital Economy Agency

International Commitments
  • No Data

Bermuda

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Personal Information Protection Act (PIPA) (2016)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Cybersecurity Provisions

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Bolivia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Bill of Personal Data Protection (2019)
Other Data Privacy Laws
  • Ley General de Telecomunicaciones, Tecnologías de Información y Comunicación (in Spanish) (2011)
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Breach Notification

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart City
  • Facial Recognition
  • Predictive Policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Bosnia and Herzegovina

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law on Protection of Personal Data ("Official Gazette of BIH," nos. 49/06, 76/11 and 89/11) (2006/2011)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • Member of the Budapest Convention (2006)

Botswana

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act–Act No. 32 (2018)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Transport and Communications

International Commitments
  • No Data

Brazil

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Brazilian General Data Protection Law (LGPD) (2018)
Other Data Privacy Laws
  • Brazil Internet Act (2014)
  • Protection of Personal Data Bill (2011)
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • General right to encryption
  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Agency: No Data

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework
International Commitments
  • UN GGE 2019/2021 member

Bulgaria

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law for Protection of Personal Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Resilient Bulgaria 2020 (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Transport, Information Technology and Communications

International Commitments
  • Member of the Budapest Convention (2005)

Burkina Faso

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 010-2004/AN on the Protection of Personal Data (2004)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2019-2023 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Agency for the Promotion of Information and Communication Technologies

International Commitments
  • No Data

Cambodia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cambodian ICT Masterplan 2020 (2014)

  • Capacity-building to detect/respond to cyber threats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Posts and Telecommunications

International Commitments
  • No Data

Canada

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Personal Information Protection and Electronic Documents Act ('PIPEDA') (2000) & Consumer Privacy Protection Act (DRAFT)
Other Data Privacy Laws
  • Regional Acts
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Import/export controls

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Canada's Vision for Security and Prosperity in the Digital Age (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Canadian Centre for Cyber Security

International Commitments
  • Member of the Budapest Convention (2015)

Cape Verde

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Law (2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Data Localization Provisions - Conditional Restrictions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Cayman Islands

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Law (2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Data Localization Provisions - Conditional Restrictions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Chad

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 007/PR/2015 on the Protection of Personal Data (2015)
Other Data Privacy Laws
  • Law No. 006/PR/2015 on the creation of the National Agency for Computer Security and Electronic Certification
  • Law No. 008/PR/2015 on Electronic transactions
  • Law No. 009/PR/ on Cybersecurity and Cybercrime
  • Law No. 001/PR/2017 on the Penal Code
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Chile

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law 19,628/1999 "On the protection of private life," commonly referred to as "Personal Data Protection Law" (1999/2011)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Policy (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Interministerial Committee on Cyber Security

International Commitments
  • Member of the Budapest Convention (2017)

China

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Information Protection Law (DRAFT)
Other Data Privacy Laws
  • The Cybersecurity Law (2018)
  • The Decision of the Standing Committee of the National People’s Congress on Strengthening the Network Information Protection (2012)
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Licensing/registration requirements
  • Import/export controls
  • Obligations on providers to assist authorities
  • Other restrictions

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyberspace Security Strategy (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Cyberspace Administration of China

International Commitments
  • UN GGE 2019/2021 member

Colombia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Statutory Law 1266 of 2008 (Law 1266)
  • Statutory Law 1581 of 2012 (Law 1581)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Other restrictions

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Digital Security Policy (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: No Data

International Commitments
  • Member of the Budapest Convention (2004)

Costa Rica

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Law No. 7975, the Undisclosed Information Law (2000)
  • Law No. 8968, Protection in the Handling of the Personal Data of Individuals
Active Legal Provisions
  • National Data Protection Authority
  • Cybersecurity Provisions
  • Breach Notification

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Science, Technology and Telecommunications

International Commitments
  • Member of the Budapest Convention (2018)

Côte d'Ivoire

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • LAW No. 2013 450 dated June 19, 2013 on the protection of personal data (2013)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Enforcement Through Fine
  • Online Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • Member of the Budapest Convention (since 2013)
  • UN GGE 2019/2021 member

Croatia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Act on Personal Data Protection
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Council

International Commitments
  • Member of the Budapest Convention (2004)

Cuba

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • Licensing/registration requirements
  • Other restrictions

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Cyprus

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • The Processing of Personal Data (Protection of the Individual) Law
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Strategy of the Republic of Cyprus (2012)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Office of the Commissioner of Electronic Communications and Postal Regulation (OCECPR)

International Commitments
  • Member of the Budapest Convention (2020)

Czech Republic

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on Personal Data Protection
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects are notified of surveillance by intelligence services
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy of the Czech Republic 2021-2025 (2021)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats

National Cybersecurity Agency: National Cyber and Information Security Agency (NCISA)

International Commitments
  • Member of the Budapest Convention (2013)

Denmark

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Act on Processing of Personal Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Danish Cyber and Information Security Strategy 2018-2021 (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Centre for Cyber Security (CCS)

International Commitments
  • Member of the Budapest Convention (2005)

Dominican Republic

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 172-13 on the Protection of Personal Data (2013)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Cybersecurity Provisions
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Decree No. 230-18, establishing and regulating the National Cybersecurity Strategy 2018-2021 (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Interinstitutional Commission against Crimes and High Technology Crimes

International Commitments
  • Member of the Budapest Convention (2013)

Ecuador

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Organic Law on Data Protection (2021)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

El Salvador

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Ley de Comercio Electronico y Comunicaciones
Active Legal Provisions
  • No Data

Encryption Policies

  • Obligations on providers to assist authorities
  • Other restrictions

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Egypt

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Law No.151 of 2020 (2020)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Import/export controls
  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2017-2021 (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Egyptian Supreme Cybersecurity Council (ESCC)

International Commitments
  • No Data

Estonia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Data Protection Act
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Strategy 2019-2022 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Cyber Security Council

International Commitments
  • Member of the Budapest Convention (2004)
  • UN GGE 2019/2021 member

Ethiopia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Freedom of the Mass Media and Access to Information Proclamation No. 590/2008 (2008)
  • 2005 Criminal Code of the Federal Democratic Republic of Ethiopia
  • 1960 Civil Code
  • Computer Crime Proclamation No. 958/2016
Active Legal Provisions
  • Online Data Privacy Element

Encryption Policies

  • Licensing/registration requirements
  • Import/export controls
  • Other restrictions

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Critical Mass Cyber Security Requirement Standard (2017)

  • Details not publicly available

National Cybersecurity Agency: Information Network Security Agency (INSA)

International Commitments
  • Member of the Budapest Convention (2005)

Finland

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Account Act (1997)
  • Personal Data Act
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • General right to encryption
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects are notified of surveillance by intelligence services
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Finland's Cyber Security Strategy (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Centre Finland (NCSC-FI)

International Commitments
  • Member of the Budapest Convention (2007)

France

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Personal Data Act
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • General right to encryption
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Digital Security Strategy (2015)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: French Network and Information Security Agency (ANSSI)

International Commitments
  • Member of the Budapest Convention (2006)
  • UN GGE 2019/2021 member

Germany

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Federal Data Protection Act (in English) Bundesdatenschutzgesetz - BDSG (in German)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects are notified of surveillance by intelligence services
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Security Strategy for Germany (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Federal Office for Information Security (BSI)

International Commitments
  • Member of the Budapest Convention (2009)
  • UN GGE 2019/2021 member

Ghana

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act (Act 843) (2012)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Ghana National Cyber Security Policy & Strategy (2015)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Centre (NCSC)

International Commitments
  • Member of the Budapest Convention (2018)

Greece

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on the Protection of Individuals with Regard to the Processing of Personal Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2020-2025 (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Cyber Security Authority

International Commitments
  • Member of the Budapest Convention (2017)

Guatemala

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of the Interior

International Commitments
  • Member of the Budapest Convention (2005)

Guernsey

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection (Bailiwick of Guernsey) Law, 2017 (2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Honduras

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law for the Protection of Confidential Personal Data (2019)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Hong Kong

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Personal Data (Privacy) Ordinance (Cap. 486) (1996/2012)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Cybersecurity Provisions
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Hungary

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Act on Informational Self-Determination and Freedom of Information
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy of Hungary (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Coordination Council

International Commitments
  • Member of the Budapest Convention (2013)

Iceland

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on the Protection and Processing of Personal Data 1989
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Icelandic National Cyber Security Strategy 2015-2026 (2015)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Cyber Security Council

International Commitments
  • Member of the Budapest Convention (2007)

India

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Bill 2019 (DRAFT)
Other Data Privacy Laws
  • Information Technology Act 2000
Active Legal Provisions
  • Data Protection Officers
  • Data Localization Provisions - Local Copy
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Mandatory minimum or maximum encryption strength
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Policy (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Critical Information Infrastructure Protection Centre (NCIIPC)

International Commitments
  • UN GGE 2019/2021 member

Indonesia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Bill on the Protection of Private Personal Data (DRAFT)
Other Data Privacy Laws
  • Law No. 11 of 2008 regarding Electronic Information and Transactions ("EIT Law")
  • Law No. 19 of 2016 regarding the Amendment of EIT Law
  • Government Regulation No. 71 of 2019 Regarding Provisions of Electronic Systems and Transactions
Active Legal Provisions
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Agency: National Cyber and Encryption Agency (BSSN)

International Commitments
  • UN GGE 2019/2021 member

Iran

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection and Safeguarding Draft Act (DRAFT)
Other Data Privacy Laws
  • Law on Publication and Access to Data (2009)
  • Electronic Commerce Law (2004)
  • Cybercrime Law (2009)
Active Legal Provisions
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • Other restrictions

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Agency: Supreme Council of Cyberspace (SCC)

International Commitments
  • Member of the Budapest Convention (2005)

Ireland

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Data Protection Act, 1988
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Licensing/registration requirements

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Israel National Cyber Directorate

International Commitments
  • Member of the Budapest Convention (2016)

Israel

Main Data Privacy Laws (Year Enacted/Updated)

The Protection of Privacy Law (1992)

  • National data protection authority
  • Registration requirement
  • Data protection officers
  • Cybersecurity provisions
Other Data Privacy Laws
  • Privacy Protection Act (1981)
Government Data Collection Laws
  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data
Encryption Policies
  • Licensing/registration requirements
AI Surveillance
Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • U.S. tech

Italy

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Decreto Legislativo 30 giugno 2003, n. 196 - Codice in materia di protezione dei dati personali (in Italian)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
Source:
  • Chinese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Strategic Framework for Cyberspace Security (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Cybersecurity Management Board (NSC)

International Commitments
  • Member of the Budapest Convention (2008)

Jamaica

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Act (2020)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Jamaica National Cyber Security Strategy (2015)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Information Communication Technology Division

International Commitments
  • No Data

Japan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Act on the Protection of Personal Information (2003/2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Strategy 2018 (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Cybersecurity Strategic Headquarters

International Commitments
  • Member of the Budapest Convention (2012)
  • UN GGE 2019/2021 member

Jersey

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection (Jersey) Law (2018); Data Protection Authority (Jersey) Law (2018)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Jordan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (NCSS) 2018-2023 (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Cyber Security Center (NCSC)

International Commitments
  • UN GGE 2019/2021 member

Kazakhstan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law of the Republic of Kazakhstan No. 94-V "On Personal Data and Its Protection" (2013)
Other Data Privacy Laws
  • Law on Informatisation
  • Law on Communication
  • Labour Code of Kazakhstan
Active Legal Provisions
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Concept 2017-2020/Cybershield of Kazakhstan (2017)

  • Capacity-building to detect/respond to cyber threats
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan

International Commitments
  • UN GGE 2019/2021 member

Kenya

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act (2012/2019)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • Japanese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2014 (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Kenya National Computer Security Incident Response Team - Coordination Centre

International Commitments
  • UN GGE 2019/2021 member

Kiribati

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • TNo Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Kiribati National Cybersecurity Strategy 2020 (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: ICT Policy and Development Division

International Commitments
  • Member of the Budapest Convention (2005)

Kuwait

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 20 (the E-Commerce Law) (2014)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Communication and Information Technology Regulatory Authority (CITRA)

International Commitments
  • No Data

Kyrgyzstan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law of the Kyrgyz Republic on Personal Data No.58 (2008)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Strategy for 2019-2023 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: State Committee for Information Technology and Communications

International Commitments
  • No Data

Laos

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law on Electronic Data Protection (2017)
Other Data Privacy Laws
  • Law on Electronic Transactions (2012)
  • Law on Cyber Crime (2015)
  • Penal Code (2017)
Active Legal Provisions
  • National Data Protection Authority
  • Cybersecurity Provisions
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Latvia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on Protection of Personal Data of Natural Persons
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Security Strategy 2019-2022 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Policy Coordination Section

International Commitments
  • Member of the Budapest Convention (2007)

Lebanon

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Predictive policing
Source:
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Lebanon National Cyber Security Strategy (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Telecommunications Regulatory Authority

International Commitments
  • No Data

Lesotho

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act (2012)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Breach Notification

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Lithuania

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on Legal Protection of Personal Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Centre (NCSC)

International Commitments
  • Member of the Budapest Convention (2004)

Luxembourg

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on Legal Protection of Personal Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services are authorized to conduct surveillance for economic purposes
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy III (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Cybersecurity Board (CSB)

International Commitments
  • Member of the Budapest Convention (2015)

Macau

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Macau personal data protection Law no. 8/2005 of August 22nd (2005)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Madagascar

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 2014-038 relating to protection of personal data (2015)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Malaysia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 2014-038 relating to protection of personal data (2015)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Malaysia Cyber Security Strategy 2020-2024 (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Agency

International Commitments
  • No Data

Malta

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Data Protection Act (2001)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities
  • Other Restrictions

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Malta Cyber Security Strategy 2016 (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Committee

International Commitments
  • Member of the Budapest Convention (2012)

Mauritania

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2019-2022 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: No Data

International Commitments
  • No Data

Mauritius

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act (2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy 2014-2019 (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: IT Security Unit

International Commitments
  • Member of the Budapest Convention (2014)
  • UN GGE 2019/2021 member

Mexico

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Federal Law on the Protection of Personal Data (2010)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Inter-secretarial Commission for the Development of Electronic Government (CIDGE)

International Commitments
  • Member of the Budapest Convention (2005)
  • UN GGE 2019/2021 member

Moldova

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No. 133 on Personal Data Protection (2011)
Other Data Privacy Laws
  • Law No. 182 of 10 July 2008 regarding the approval of the National Centre for Personal Data Protection regulation, structure, staff-limit and its financial arrangements
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Programme (2015)

  • Capacity-building to detect/respond to cyber threats
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Information Technology and Cyber Security Service

International Commitments
  • Member of the Budapest Convention (2009)

Monaco

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Law No.1462 (2018)
Other Data Privacy Laws
  • Act Controlling Personal Data Processing (1993)
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Monaco Cyber Security Agency

International Commitments
  • Member of the Budapest Convention (2017)

Mongolia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Facial recognition
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Program on Information Security 2010-2015 (2010)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Cyber Security Department

International Commitments
  • No Data

Montenegro

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law on Protection of Personal Data (2008/2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Security Strategy 2018-2021 (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats

National Cybersecurity Agency: Information Security Council

International Commitments
  • Member of the Budapest Convention (2010)

Morocco

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No 09-08 on the protection of people toward data protection of a personal nature (2009)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Online Data Privacy Element

Encryption Policies

  • Licensing/registration requirements
  • Import/export controls
  • Other restrictions

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2012)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: General Directorate of Information Systems Security

International Commitments
  • UN GGE 2019/2021 member

Mozambique

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Electronic Transactions Law (Law No.3/2017) (2017)
Other Data Privacy Laws
  • The Civil Code (Decree-Law no. 47344, of November 25, 1966)
  • The Penal Code (Law n.º 35/2014 of December 31)
  • The Labour Law (Law n.º 23/2007, of August 1)
  • The Electronic Transactions Law (Law n.º 3/2017, of January 9)
Active Legal Provisions
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Myanmar

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • Other restrictions

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Chinese tech
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Agency: Department of Information Technology and Cyber Security

International Commitments
  • No Data

Netherlands

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Personal Data Protection Act 1998
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Agenda (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Cyber Security Centre (NCSC)

International Commitments
  • Member of the Budapest Convention (2007)
  • UN GGE 2019/2021 member

New Zealand

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Privacy Act (2020)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
  • U.S. tech
Source:
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

New Zealand’s Cyber Security Strategy 2019 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Cyber Policy Office

International Commitments
  • No Data

Nigeria

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Federal Privacy Act (1988)
Other Data Privacy Laws
  • Child Rights Act (2003)
  • Freedom of Information Act (2011)
  • Cybercrimes Act (2015)
  • Consumer Protection Framework (2016)
  • Nigerian Communications Commission Regulation (2011)
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Policy and Strategy (2021)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: ngCERT

International Commitments
  • No Data

North Macedonia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law on Personal Data Protection (2005/2020)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy of the Republic of Macedonia (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Information Society and Administration

International Commitments
  • Member of the Budapest Convention (2005)

Norway

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Personal Data Act 2000
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy for Norway (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Norwegian National Security Authority

International Commitments
  • Member of the Budapest Convention (2006)
  • UN GGE 2019/2021 member

Pakistan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Bill 2020 (DRAFT)
Other Data Privacy Laws
  • Prevention of Electronic Crimes Act (2016)
Active Legal Provisions
  • Data Localization Provisions - Local Only
  • Online Data Privacy Element

Encryption Policies

  • Licensing/registration requirements
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Panama

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Law (2019)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Strategy for Cyber Security and Critical Infrastructure (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Authority for Government Innovation

International Commitments
  • Member of the Budapest Convention (2014)

Paraguay

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Personal Credit Data Protection Law (2020)
  • Electronic Commerce Law (2013)
Active Legal Provisions
  • Data Localization Provisions - Conditional restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Plan: Challenges, Roles and Commitments (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Secretariat of Information and Communication Technologies (SENATICS)

International Commitments
  • No Data

Peru

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Personal Data Protection Law No.29733 (2011)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Philippines

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Privacy Act of (2012)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Cybersecurity Provisions
  • Breach Notification

Encryption Policies

  • Mandatory minimum or maximum encryption strength

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Plan 2022 (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats

National Cybersecurity Agency: Cybercrime Investigation and Coordination Center (CICC)

International Commitments
  • No Data

Poland

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Act on the Protection of Personal Data 1997
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Strategy of the Republic of Poland, 2019-2024 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Ministry of Digital Affairs

International Commitments
  • Member of the Budapest Convention (2015)

Portugal

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Lei da proteçao de dados pessoais 1991 (in Portuguese)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Data subjects are notified of surveillance by intelligence services
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Strategy for Cyberspace Security 2019-2023 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Cyber Security Centre Portugal

International Commitments
  • Member of the Budapest Convention (2010)

Qatar

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law No. (13) of 2016 Concerning Personal Data Protection (2016)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Cybersecurity Provisions
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Committee

International Commitments
  • No Data

Romania

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Law on the Protection of Individuals with Regard to the Processing of Personal Data (2001)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Security Strategy of Romania (2013)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Cyber Security Operative Council

International Commitments
  • Member of the Budapest Convention (2004)
  • UN GGE 2019/2021 member

Russia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act No. 152 (2006/2014)
Other Data Privacy Laws
  • Information, Information Technologies and Information Protection Act No. 149 (2006)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • Licensing/registration requirements
  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Doctrine of Information Security (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Security Council of the Russian Federation

International Commitments
  • UN GGE 2019/2021 member

Rwanda

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Policy (2015)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Authority (NCSA)

International Commitments
  • Member of the Budapest Convention (2005)

Saint Lucia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Act 2011 (2011)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Samoa

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Samoa National Cybersecurity Strategy 2016-2021 (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National ICT Steering Committee

International Commitments
  • No Data

Saudi Arabia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2020)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: National Cybersecurity Authority (NCA)

International Commitments
  • No Data

Senegal

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Act (Loi No. 2008-12 du 25 janvier 2008 sur la protection des données à caractère personnel) (2008)
Other Data Privacy Laws
  • Information, Information Technologies and Information Protection Act No. 149 (2006)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Enforcement Through Fine

Encryption Policies

  • General right to encryption
  • Mandatory minimum or maximum encryption strength
  • Licensing/registration requirements
  • Import/export controls

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2022 (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of the Digital Economy and Telecommunications

International Commitments
  • Member of the Budapest Convention (2017)

Serbia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Law (2008/2018)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Chinese tech
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Strategy for the Development of Information Security in the Republic of Serbia for the period 2017-2020 (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Information and Communications Technologies Department

International Commitments
  • Member of the Budapest Convention (2009)

Singapore

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Personal Data Protection Act (2012)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Enforcement Through Fine

Encryption Policies

  • Import/export controls
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Singapore's Cybersecurity Strategy (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: The Cyber Security Agency of Singapore (CSA)

International Commitments
  • UN GGE 2019/2021 member

Slovenia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Personal Data Protection Act 1990
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cyber Security Strategy (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Information Security Administration (ISARS)

International Commitments
  • Member of the Budapest Convention (2005)

Slovakia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Act on the Protection of Personal Data 1992
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

The National Cybersecurity Strategy 2021-2025 (2021)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Security Authority

International Commitments
  • Member of the Budapest Convention (2008)

South Africa

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Protection of Personal Information Act 4 (2013)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data localization provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Licensing/registration requirements
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Policy Framework for South Africa (2015)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: State Security Agency

International Commitments
  • UN GGE 2019/2021 member

South Korea

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Personal Information Protection Act (2011)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects are notified of surveillance by intelligence services
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Center

International Commitments
  • No Data

Spain

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Organic Law 15/1999 on Personal Data Protection
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • There are public cases of national intelligence services violating surveillance laws
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cybersecurity Council

International Commitments
  • Member of the Budapest Convention (2010)

Sri Lanka

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Act to Provide for the Regulation of Processing of Personal Data (DRAFT)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Information and Cyber Security Strategy of Sri Lanka (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Sri Lanka Computer Emergency Readiness Team – Coordination Centre (Sri Lanka CERT|CC)

International Commitments
  • Member of the Budapest Convention (2015)

Sweden

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
  • Personal Data Act 1998
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • There are public cases of national intelligence services violating surveillance laws
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

A National Cyber Security Strategy (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Swedish Civil Contingencies Agency (MSB)

International Commitments
  • Member of the Budapest Convention (2021)

Switzerland

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Federal Act on Data Protection (1992/2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Strategy for the Protection of Switzerland Against Cyber Risks 2018-2022 (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Centre (NCSC)

International Commitments
  • Member of the Budapest Convention (2012)
  • UN GGE 2019/2021 member

Syria

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • Licensing/registration requirements
  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Information Security Policy (2014)

National Cybersecurity Agency: National Agency for Network Services (NANS)

International Commitments
  • No Data

Taiwan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Law (2010/2015)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Facial recognition
Source:
  • Japanese tech

Government Data Collection Laws

  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Program of Taiwan (2021)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Department of Cyber Security & National Center for Cyber Security Technology

International Commitments
  • No Data

Tajikistan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Law, No.1537 (2018)
Other Data Privacy Laws
  • Protection Data Law, No. 631 (2002)
  • Informatization Law, No. 40 (2001)
  • Information Law, No. 609 (2002)
Active Legal Provisions
  • Cybersecurity Provisions
  • Enforcement Through Fine
  • National Data Protection Authority

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Concept of Information Security of the Republic of Tajikistan (2003)

  • Capacity-building to detect/respond to cyber threats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Centre of Information-Communication Technologies

International Commitments
  • No Data

Thailand

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Personal Data Protection Act (2011/2019)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • Companies can challenge orders to provide personal data to law enforcement authorities

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Strategy 2017-2021 (2017)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Digital Economy and Society (MDES)

International Commitments
  • No Data

Trinidad and Tobago

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection Act (2011)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy (2012)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of National Security

International Commitments
  • No Data

Tunisia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law No.2004-63 on the Protection of Personal Data (2004/2016)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions

Encryption Policies

  • Licensing/registration requirements
  • Import/export controls
  • Other restrictions

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cybersecurity Agency: National Agency for Computer Security (ANSI)

International Commitments
  • No Data

Turkey

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law on the Protection of Personal Data No. 6698 (2016)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy 2016-2019 (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Transport and Infrastructure

International Commitments
  • Member of the Budapest Convention (2015)

Turkmenistan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law of Turkmenistan No. 519-V "On Information about Private Life and Its Protection" (2017)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • Data Localization Provisions - Local Copy
  • Cybersecurity Provisions
  • Online Data Privacy Element

Encryption Policies

  • No Data

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

UAE

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Data Protection (Amendment) Regulation (2018)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Other restrictions

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy 2019 (2019)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Telecommunications Regulatory Authority

International Commitments
  • No Data

Uganda

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection and Privacy Act (2015)
Other Data Privacy Laws
  • Access to Information Act (2005)
  • Regulation of Interception of Communications Act (2010)
  • Computer Misuse Act (2011)
  • Registration of Persons Act, 2015
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Information Security Policy (2014)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats

National Cybersecurity Agency: National Information Technology Authority-Uganda (NITA-U)

International Commitments
  • No Data

Ukraine

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • The Law of Ukraine No. 2297 VI "On Personal Data Protection" (2010/2013)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Cybersecurity Strategy (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Coordination Center for Cybersecurity

International Commitments
  • Member of the Budapest Convention (2006)

United Kingdom

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • UK General Data Protection Regulation (UK GDPR) (2018/2019)
Other Data Privacy Laws
  • Data Protection Act 2018
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

National Cyber Security Strategy 2016-2021 (2016)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: National Cyber Security Centre (NCSC)

International Commitments
  • Member of the Budapest Convention (2011)
  • UN GGE 2019/2021 member

United States

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Privacy Act of 1974 (Does Not Include Provisions Related to Online Privacy)
  • State Laws
Active Legal Provisions
  • No Data

Encryption Policies

  • Import/export controls
  • Obligations on providers to assist authorities

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech
  • U.S. tech

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Data subjects have the right to court review of surveillance measures taken by intelligence services
  • Companies can challenge orders to provide personal data to law enforcement authorities
  • Intelligence services can compel companies to provide access to data
  • There are public cases of national intelligence services violating surveillance laws

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

White House National Cyber Strategy (2018) & Department of Homeland Security Cybersecurity Strategy (2018)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry

National Cybersecurity Agency: Cybersecurity and Infrastructure Security Agency (CISA)

International Commitments
  • Member of the Budapest Convention (2007)
  • UN GGE 2019/2021 member

Uruguay

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Act Law No. 18331 (2008)
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
  • Predictive policing
  • Chinese tech
  • U.S. tech
Source:
  • Chinese tech
  • U.S. tech
  • Japanese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • UN GGE 2019/2021 member

Uzbekistan

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Law of the Republic of Uzbekistan No. ZRU-547 “On Personal Data” (2019)
Other Data Privacy Laws
  • Law No. 439-II 'On Principles and Guarantees of Freedom of Information' (2002)
  • Law No. 560-II 'On Informatization' (2003)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Localization Provisions - Conditional Restrictions
  • Cybersecurity Provisions
  • Enforcement Through Fine

Encryption Policies

  • No Data

AI Surveillance

Type:
  • Smart city
  • Facial recognition
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • No Data

Vanuatu

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • No Data
Active Legal Provisions
  • No Data

Encryption Policies

  • General right to encryption
  • Licensing/registration requirements
  • Import/export controls

AI Surveillance

  • No Data

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Vanuatu National Cyber Security Strategy (2021)

  • Capacity-building to detect/respond to cyber threats
  • Protection of critical infrastructure
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Office of the Government Chief Information Office

International Commitments
  • No Data

Vietnam

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • No Data
Other Data Privacy Laws
  • Cybersecurity Law (2013)
  • Network Information Security Law (2018)
  • Constitution (2013)
  • Civil Code (2013)
  • Law on Protection of Consumers' Rights (2010)
  • Law on Information Technology (2006)
  • E-transactions Law (2005)
Active Legal Provisions
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • Licensing/registration requirements
  • Import/export controls
  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities
  • Other restrictions

AI Surveillance

  • No Data

Government Data Collection Laws

  • Intelligence services operate surveillance programs to protect national security
  • Intelligence services are authorized to conduct surveillance for economic purposes
  • Intelligence services can compel companies to provide access to data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments

Decision approving the orientation, objectives and duties to ensure the cyber information security for the period 2016-2020 (2016)

  • Capacity-building to detect/respond to cyber threats
  • Public education/awareness-raising about cyberthreats
  • Commitment to develop cybersecurity research/industry
  • Commitment to develop domestic regulatory/legal framework

National Cybersecurity Agency: Ministry of Information and Communications

International Commitments
  • No Data

Zambia

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Data Protection Act No. 3 (2021)
Other Data Privacy Laws
  • Electronic Communications and Transactions Act No. 4 (2021)
  • Cyber Security and Cyber Crimes Act No. 2 (2021)
  • Information and Communications Technologies Act No. 15 (2009)
Active Legal Provisions
  • National Data Protection Authority
  • Registration Requirement
  • Data Protection Officers
  • Data Localization Provisions - Local Only
  • Cybersecurity Provisions
  • Breach Notification
  • Enforcement Through Fine
  • Online Data Privacy Element

Encryption Policies

  • General right to encryption
  • Licensing/registration requirements
  • Other restrictions

AI Surveillance

Type:
  • Facial recognition
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • Member of the Budapest Convention (since 2013)
  • UN GGE 2019/2021 member

Zimbabwe

Data Privacy Laws (Year Enacted/Updated)

Comprehensive Data Privacy Law
  • Cybersecurity and Data Protection Bill of 2019 (DRAFT)
Other Data Privacy Laws
  • Constitution of Zimbabwe Amendment 20 (2013)
  • Freedom of Information Act (2020)
Active Legal Provisions
  • No Data

Encryption Policies

  • Obligations on providers to assist authorities
  • Obligations on individuals to assist authorities

AI Surveillance

Type:
  • Facial recognition
  • Predictive policing
Source:
  • Chinese tech

Government Data Collection Laws

  • No Data

Cybersecurity Commitments (Year Adopted/Ratified)

Domestic Commitments
  • No Data
International Commitments
  • Member of the Budapest Convention (since 2013)
  • UN GGE 2019/2021 member
SOURCES: DLA PIPER: GLOBAL DATA PROTECTION LAWS OF THE WORLD FULL HANDBOOK, BAKER MCKENZIE – GLOBAL SURVEILLANCE LAW COMPARISON, GLOBAL PARTNERS DIGITAL – WORLD MAP OF ENCRYPTION POLICIES, PRIVACY INTERNATIONAL – THE GLOBAL SURVEILLANCE INDUSTRY, CARNEGIE ENDOWMENT – AI GLOBAL SURVEILLANCE INDEX, PRIVACY INTERNATIONAL – TELECOMMUNICATION DATA AND COVID-19, PRIVACY INTERNATIONAL – APPS AND COVID-19
Loading graphics