By identifying key players, quantifying relative influence, and assessing the competitive landscape, FP Analytics breaks down complex foreign policy issues by mapping out spheres of influence and the risks and opportunities these topics present. LEARN MORE
Global Data Governance
Database of Policies
UPDATED: Sept. 15, 2021
PUBLISHED: Oct. 6, 2020
Foreign Policy Analytics’ (FPA’s) Global Data Governance Power Map details emerging trends in private companies’ and governments’ data collection practices. These trends include the proliferation of data privacy and data localization laws, governments’ expanding data collection practices, changes in global encryption laws, the rising use of AI for data collection, and the proliferation of international cybersecurity commitments. Throughout the Power Map series, laws and policies related to these trends are catalogued and graphically broken down for readers.
As a reference and navigable tool, all of the practices and regulations chronicled in the Power Map series have been consolidated in FPA’s Global Data Governance Database below. This database provides a comprehensive regional and country-level breakdown of global data governance practices in 138 countries worldwide. For easy navigation, this searchable database can be sorted by country or region. For a deeper dive into each global data governance practice chronicled below, see the corresponding Power Map section.
Filter by location:
Filter by data policies/technology:
Afghanistan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyberspace Security Strategy (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Information System Security Directorate (ISSD)
International Commitments
- No Data
Albania
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Authority for Electronic Certification and Cyber Security (NAECCS)
International Commitments
- Member of the Budapest Convention (2004)
Angola
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Law (PDPL) (2000)
Other Data Privacy Laws
- Electronic Communications and Information Society Services Law (2011)
- Protection of Information Systems and Networks Law (2017)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Argentina
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Law (PDPL) (2000)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National data protection authority
- Registration requirement
- Data localization provisions - Local Copy
- Cybersecurity provisions
- Enforcement through fine
Encryption Policies
- No Data
AI Surveillance
- Facial recognition
- Predictive policing
- Chinese tech
- Japanese tech
- Chinese tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Program for Critical Information Infrastructure and Cybersecurity
International Commitments
- Member of the Budapest Convention (2018)
Armenia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Armenia 2020 National Security Strategy (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Program for Critical Information Infrastructure and Cybersecurity
International Commitments
- Member of the Budapest Convention (2007)
Australia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Federal Privacy Act (1988)
Other Data Privacy Laws
- Information Privacy Act (2009)
Active Legal Provisions
- National Data Protection Authority
- Breach Notification
- Cybersecurity Provisions
- Data Localization Provisions - Conditional Restrictions
- Enforcement Through Fine
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial Recognition
- Predictive Policing
- Chinese Tech
- U.S. Tech
- Japanese Tech
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Australia’s Cybersecurity Strategy 2020 (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Australian Signals Directorate
International Commitments
- Member of the Budapest Convention (since 2013)
- UN GGE 2019/2021 member
Austria
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Datenschutzgesetz (2000)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Austrian Cyber Security Strategy (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Cyber Security Steering Group
International Commitments
- Member of the Budapest Convention (2012)
Azerbaijan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Strategy of the Republic of Azerbaijan on Information Security and Cybersecurity for 2021-2025 (DRAFT)
National Cybersecurity Agency: Cyber Security Center
International Commitments
- Member of the Budapest Convention (2010)
Bahrain
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law No. 30 of 2018 with respect to Personal Data Protection (PDPL) (2008/2020)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
Encryption Policies
- No Data
AI Surveillance
- Facial Recognition
- Predictive Policing
- Chinese Tech
- Chinese Tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Information & eGovernment Authority
International Commitments
- No Data
Bangladesh
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- Smart City
- Facial Recognition
- Predictive Policing
- Chinese Tech
- Chinese Tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
The National Cybersecurity Strategy of Bangladesh (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: No Data
International Commitments
- No Data
Belarus
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law on Personal Data Protection (DRAFT)
Other Data Privacy Laws
- Data Protection Law (2008)
- Population Register Law (2008)
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- Import/export controls
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Belgium
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Security Strategy, Securing Cyberspace (2012)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Centre for Cybersecurity Belgium (CCB)
International Commitments
- Member of the Budapest Convention (2012)
Belize
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy - Towards A Secure Cyberspace 2020-2023 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Central Information Technology Office & National Cyber Security Task Force
International Commitments
- No Data
Benin
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Digital Code (2018)
Other Data Privacy Laws
- LAW N° 2009-09 OF MAY 22, 2009 Dealing with the protection of Personally Identifiable Information (PII) in the Republic of Benin (2009)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Digital Security Strategy (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Digital Economy Agency
International Commitments
- No Data
Bermuda
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Personal Information Protection Act (PIPA) (2016)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Cybersecurity Provisions
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Bolivia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Bill of Personal Data Protection (2019)
Other Data Privacy Laws
- Ley General de Telecomunicaciones, Tecnologías de Información y Comunicación (in Spanish) (2011)
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Breach Notification
Encryption Policies
- No Data
AI Surveillance
- Smart City
- Facial Recognition
- Predictive Policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Bosnia and Herzegovina
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law on Protection of Personal Data ("Official Gazette of BIH," nos. 49/06, 76/11 and 89/11) (2006/2011)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- Member of the Budapest Convention (2006)
Botswana
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act–Act No. 32 (2018)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Transport and Communications
International Commitments
- No Data
Brazil
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Brazilian General Data Protection Law (LGPD) (2018)
Other Data Privacy Laws
- Brazil Internet Act (2014)
- Protection of Personal Data Bill (2011)
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- General right to encryption
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Agency: No Data
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
International Commitments
- UN GGE 2019/2021 member
Bulgaria
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law for Protection of Personal Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Resilient Bulgaria 2020 (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Transport, Information Technology and Communications
International Commitments
- Member of the Budapest Convention (2005)
Burkina Faso
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 010-2004/AN on the Protection of Personal Data (2004)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2019-2023 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Agency for the Promotion of Information and Communication Technologies
International Commitments
- No Data
Cambodia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cambodian ICT Masterplan 2020 (2014)
- Capacity-building to detect/respond to cyber threats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Posts and Telecommunications
International Commitments
- No Data
Canada
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Personal Information Protection and Electronic Documents Act ('PIPEDA') (2000) & Consumer Privacy Protection Act (DRAFT)
Other Data Privacy Laws
- Regional Acts
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Import/export controls
AI Surveillance
- Facial recognition
- Predictive policing
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Canada's Vision for Security and Prosperity in the Digital Age (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Canadian Centre for Cyber Security
International Commitments
- Member of the Budapest Convention (2015)
Cape Verde
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Law (2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Data Localization Provisions - Conditional Restrictions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Cayman Islands
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Law (2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Data Localization Provisions - Conditional Restrictions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Chad
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 007/PR/2015 on the Protection of Personal Data (2015)
Other Data Privacy Laws
- Law No. 006/PR/2015 on the creation of the National Agency for Computer Security and Electronic Certification
- Law No. 008/PR/2015 on Electronic transactions
- Law No. 009/PR/ on Cybersecurity and Cybercrime
- Law No. 001/PR/2017 on the Penal Code
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Chile
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law 19,628/1999 "On the protection of private life," commonly referred to as "Personal Data Protection Law" (1999/2011)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Policy (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Interministerial Committee on Cyber Security
International Commitments
- Member of the Budapest Convention (2017)
China
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Information Protection Law (DRAFT)
Other Data Privacy Laws
- The Cybersecurity Law (2018)
- The Decision of the Standing Committee of the National People’s Congress on Strengthening the Network Information Protection (2012)
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Licensing/registration requirements
- Import/export controls
- Obligations on providers to assist authorities
- Other restrictions
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyberspace Security Strategy (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Cyberspace Administration of China
International Commitments
- UN GGE 2019/2021 member
Colombia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Statutory Law 1266 of 2008 (Law 1266)
- Statutory Law 1581 of 2012 (Law 1581)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Other restrictions
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Digital Security Policy (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: No Data
International Commitments
- Member of the Budapest Convention (2004)
Costa Rica
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Law No. 7975, the Undisclosed Information Law (2000)
- Law No. 8968, Protection in the Handling of the Personal Data of Individuals
Active Legal Provisions
- National Data Protection Authority
- Cybersecurity Provisions
- Breach Notification
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Science, Technology and Telecommunications
International Commitments
- Member of the Budapest Convention (2018)
Côte d'Ivoire
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- LAW No. 2013 450 dated June 19, 2013 on the protection of personal data (2013)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Enforcement Through Fine
- Online Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- Member of the Budapest Convention (since 2013)
- UN GGE 2019/2021 member
Croatia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Act on Personal Data Protection
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Council
International Commitments
- Member of the Budapest Convention (2004)
Cuba
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- Licensing/registration requirements
- Other restrictions
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Cyprus
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- The Processing of Personal Data (Protection of the Individual) Law
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Strategy of the Republic of Cyprus (2012)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Office of the Commissioner of Electronic Communications and Postal Regulation (OCECPR)
International Commitments
- Member of the Budapest Convention (2020)
Czech Republic
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on Personal Data Protection
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Facial recognition
- Predictive policing
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects are notified of surveillance by intelligence services
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy of the Czech Republic 2021-2025 (2021)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
National Cybersecurity Agency: National Cyber and Information Security Agency (NCISA)
International Commitments
- Member of the Budapest Convention (2013)
Denmark
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Act on Processing of Personal Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Danish Cyber and Information Security Strategy 2018-2021 (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Centre for Cyber Security (CCS)
International Commitments
- Member of the Budapest Convention (2005)
Dominican Republic
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 172-13 on the Protection of Personal Data (2013)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Cybersecurity Provisions
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Decree No. 230-18, establishing and regulating the National Cybersecurity Strategy 2018-2021 (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Interinstitutional Commission against Crimes and High Technology Crimes
International Commitments
- Member of the Budapest Convention (2013)
Ecuador
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Organic Law on Data Protection (2021)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
El Salvador
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Ley de Comercio Electronico y Comunicaciones
Active Legal Provisions
- No Data
Encryption Policies
- Obligations on providers to assist authorities
- Other restrictions
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Egypt
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Law No.151 of 2020 (2020)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Import/export controls
- Obligations on providers to assist authorities
AI Surveillance
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2017-2021 (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Egyptian Supreme Cybersecurity Council (ESCC)
International Commitments
- No Data
Estonia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Data Protection Act
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Strategy 2019-2022 (2019)
- Capacity-building to detect/respond to cyber threats
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Cyber Security Council
International Commitments
- Member of the Budapest Convention (2004)
- UN GGE 2019/2021 member
Ethiopia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Freedom of the Mass Media and Access to Information Proclamation No. 590/2008 (2008)
- 2005 Criminal Code of the Federal Democratic Republic of Ethiopia
- 1960 Civil Code
- Computer Crime Proclamation No. 958/2016
Active Legal Provisions
- Online Data Privacy Element
Encryption Policies
- Licensing/registration requirements
- Import/export controls
- Other restrictions
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Critical Mass Cyber Security Requirement Standard (2017)
- Details not publicly available
National Cybersecurity Agency: Information Network Security Agency (INSA)
International Commitments
- Member of the Budapest Convention (2005)
Finland
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Account Act (1997)
- Personal Data Act
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- General right to encryption
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects are notified of surveillance by intelligence services
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Finland's Cyber Security Strategy (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Centre Finland (NCSC-FI)
International Commitments
- Member of the Budapest Convention (2007)
France
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Personal Data Act
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- General right to encryption
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Digital Security Strategy (2015)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: French Network and Information Security Agency (ANSSI)
International Commitments
- Member of the Budapest Convention (2006)
- UN GGE 2019/2021 member
Germany
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Federal Data Protection Act (in English) Bundesdatenschutzgesetz - BDSG (in German)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects are notified of surveillance by intelligence services
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Security Strategy for Germany (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Federal Office for Information Security (BSI)
International Commitments
- Member of the Budapest Convention (2009)
- UN GGE 2019/2021 member
Ghana
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act (Act 843) (2012)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Ghana National Cyber Security Policy & Strategy (2015)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Centre (NCSC)
International Commitments
- Member of the Budapest Convention (2018)
Greece
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on the Protection of Individuals with Regard to the Processing of Personal Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2020-2025 (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Cyber Security Authority
International Commitments
- Member of the Budapest Convention (2017)
Guatemala
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of the Interior
International Commitments
- Member of the Budapest Convention (2005)
Guernsey
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection (Bailiwick of Guernsey) Law, 2017 (2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Honduras
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law for the Protection of Confidential Personal Data (2019)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Hong Kong
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Personal Data (Privacy) Ordinance (Cap. 486) (1996/2012)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Cybersecurity Provisions
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Hungary
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Act on Informational Self-Determination and Freedom of Information
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy of Hungary (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Coordination Council
International Commitments
- Member of the Budapest Convention (2013)
Iceland
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on the Protection and Processing of Personal Data 1989
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Icelandic National Cyber Security Strategy 2015-2026 (2015)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Cyber Security Council
International Commitments
- Member of the Budapest Convention (2007)
India
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Bill 2019 (DRAFT)
Other Data Privacy Laws
- Information Technology Act 2000
Active Legal Provisions
- Data Protection Officers
- Data Localization Provisions - Local Copy
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Mandatory minimum or maximum encryption strength
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Policy (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Critical Information Infrastructure Protection Centre (NCIIPC)
International Commitments
- UN GGE 2019/2021 member
Indonesia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Bill on the Protection of Private Personal Data (DRAFT)
Other Data Privacy Laws
- Law No. 11 of 2008 regarding Electronic Information and Transactions ("EIT Law")
- Law No. 19 of 2016 regarding the Amendment of EIT Law
- Government Regulation No. 71 of 2019 Regarding Provisions of Electronic Systems and Transactions
Active Legal Provisions
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Agency: National Cyber and Encryption Agency (BSSN)
International Commitments
- UN GGE 2019/2021 member
Iran
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection and Safeguarding Draft Act (DRAFT)
Other Data Privacy Laws
- Law on Publication and Access to Data (2009)
- Electronic Commerce Law (2004)
- Cybercrime Law (2009)
Active Legal Provisions
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- Other restrictions
AI Surveillance
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Agency: Supreme Council of Cyberspace (SCC)
International Commitments
- Member of the Budapest Convention (2005)
Ireland
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Data Protection Act, 1988
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Licensing/registration requirements
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Israel National Cyber Directorate
International Commitments
- Member of the Budapest Convention (2016)
Israel
Main Data Privacy Laws (Year Enacted/Updated)
The Protection of Privacy Law (1992)
- National data protection authority
- Registration requirement
- Data protection officers
- Cybersecurity provisions
Other Data Privacy Laws
- Privacy Protection Act (1981)
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
Encryption Policies
- Licensing/registration requirements
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- U.S. tech
Italy
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Decreto Legislativo 30 giugno 2003, n. 196 - Codice in materia di protezione dei dati personali (in Italian)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Chinese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Strategic Framework for Cyberspace Security (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Cybersecurity Management Board (NSC)
International Commitments
- Member of the Budapest Convention (2008)
Jamaica
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Act (2020)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Jamaica National Cyber Security Strategy (2015)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Information Communication Technology Division
International Commitments
- No Data
Japan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Act on the Protection of Personal Information (2003/2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- Japanese tech
Government Data Collection Laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Strategy 2018 (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Cybersecurity Strategic Headquarters
International Commitments
- Member of the Budapest Convention (2012)
- UN GGE 2019/2021 member
Jersey
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection (Jersey) Law (2018); Data Protection Authority (Jersey) Law (2018)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Jordan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (NCSS) 2018-2023 (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Cyber Security Center (NCSC)
International Commitments
- UN GGE 2019/2021 member
Kazakhstan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law of the Republic of Kazakhstan No. 94-V "On Personal Data and Its Protection" (2013)
Other Data Privacy Laws
- Law on Informatisation
- Law on Communication
- Labour Code of Kazakhstan
Active Legal Provisions
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Concept 2017-2020/Cybershield of Kazakhstan (2017)
- Capacity-building to detect/respond to cyber threats
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan
International Commitments
- UN GGE 2019/2021 member
Kenya
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act (2012/2019)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- Japanese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2014 (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Kenya National Computer Security Incident Response Team - Coordination Centre
International Commitments
- UN GGE 2019/2021 member
Kiribati
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- TNo Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Kiribati National Cybersecurity Strategy 2020 (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: ICT Policy and Development Division
International Commitments
- Member of the Budapest Convention (2005)
Kuwait
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 20 (the E-Commerce Law) (2014)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Communication and Information Technology Regulatory Authority (CITRA)
International Commitments
- No Data
Kyrgyzstan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law of the Kyrgyz Republic on Personal Data No.58 (2008)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Strategy for 2019-2023 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: State Committee for Information Technology and Communications
International Commitments
- No Data
Laos
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law on Electronic Data Protection (2017)
Other Data Privacy Laws
- Law on Electronic Transactions (2012)
- Law on Cyber Crime (2015)
- Penal Code (2017)
Active Legal Provisions
- National Data Protection Authority
- Cybersecurity Provisions
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Latvia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on Protection of Personal Data of Natural Persons
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Security Strategy 2019-2022 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Policy Coordination Section
International Commitments
- Member of the Budapest Convention (2007)
Lebanon
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Predictive policing
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Lebanon National Cyber Security Strategy (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Telecommunications Regulatory Authority
International Commitments
- No Data
Lesotho
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act (2012)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Breach Notification
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Lithuania
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on Legal Protection of Personal Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Centre (NCSC)
International Commitments
- Member of the Budapest Convention (2004)
Luxembourg
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on Legal Protection of Personal Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services are authorized to conduct surveillance for economic purposes
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy III (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Cybersecurity Board (CSB)
International Commitments
- Member of the Budapest Convention (2015)
Macau
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Macau personal data protection Law no. 8/2005 of August 22nd (2005)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Madagascar
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 2014-038 relating to protection of personal data (2015)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Malaysia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 2014-038 relating to protection of personal data (2015)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- Japanese tech
Government Data Collection Laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Malaysia Cyber Security Strategy 2020-2024 (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Agency
International Commitments
- No Data
Malta
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Data Protection Act (2001)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
- Other Restrictions
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Malta Cyber Security Strategy 2016 (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Committee
International Commitments
- Member of the Budapest Convention (2012)
Mauritania
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2019-2022 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: No Data
International Commitments
- No Data
Mauritius
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act (2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy 2014-2019 (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: IT Security Unit
International Commitments
- Member of the Budapest Convention (2014)
- UN GGE 2019/2021 member
Mexico
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Federal Law on the Protection of Personal Data (2010)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Inter-secretarial Commission for the Development of Electronic Government (CIDGE)
International Commitments
- Member of the Budapest Convention (2005)
- UN GGE 2019/2021 member
Moldova
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No. 133 on Personal Data Protection (2011)
Other Data Privacy Laws
- Law No. 182 of 10 July 2008 regarding the approval of the National Centre for Personal Data Protection regulation, structure, staff-limit and its financial arrangements
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Programme (2015)
- Capacity-building to detect/respond to cyber threats
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Information Technology and Cyber Security Service
International Commitments
- Member of the Budapest Convention (2009)
Monaco
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Law No.1462 (2018)
Other Data Privacy Laws
- Act Controlling Personal Data Processing (1993)
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Monaco Cyber Security Agency
International Commitments
- Member of the Budapest Convention (2017)
Mongolia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- Facial recognition
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Program on Information Security 2010-2015 (2010)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Cyber Security Department
International Commitments
- No Data
Montenegro
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law on Protection of Personal Data (2008/2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Security Strategy 2018-2021 (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
National Cybersecurity Agency: Information Security Council
International Commitments
- Member of the Budapest Convention (2010)
Morocco
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No 09-08 on the protection of people toward data protection of a personal nature (2009)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Online Data Privacy Element
Encryption Policies
- Licensing/registration requirements
- Import/export controls
- Other restrictions
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2012)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: General Directorate of Information Systems Security
International Commitments
- UN GGE 2019/2021 member
Mozambique
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Electronic Transactions Law (Law No.3/2017) (2017)
Other Data Privacy Laws
- The Civil Code (Decree-Law no. 47344, of November 25, 1966)
- The Penal Code (Law n.º 35/2014 of December 31)
- The Labour Law (Law n.º 23/2007, of August 1)
- The Electronic Transactions Law (Law n.º 3/2017, of January 9)
Active Legal Provisions
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Myanmar
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- Other restrictions
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Agency: Department of Information Technology and Cyber Security
International Commitments
- No Data
Netherlands
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Personal Data Protection Act 1998
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Agenda (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Cyber Security Centre (NCSC)
International Commitments
- Member of the Budapest Convention (2007)
- UN GGE 2019/2021 member
New Zealand
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Privacy Act (2020)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Facial recognition
- Predictive policing
- U.S. tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
New Zealand’s Cyber Security Strategy 2019 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Cyber Policy Office
International Commitments
- No Data
Nigeria
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Federal Privacy Act (1988)
Other Data Privacy Laws
- Child Rights Act (2003)
- Freedom of Information Act (2011)
- Cybercrimes Act (2015)
- Consumer Protection Framework (2016)
- Nigerian Communications Commission Regulation (2011)
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Policy and Strategy (2021)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: ngCERT
International Commitments
- No Data
North Macedonia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law on Personal Data Protection (2005/2020)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy of the Republic of Macedonia (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Information Society and Administration
International Commitments
- Member of the Budapest Convention (2005)
Norway
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Personal Data Act 2000
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy for Norway (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Norwegian National Security Authority
International Commitments
- Member of the Budapest Convention (2006)
- UN GGE 2019/2021 member
Pakistan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Bill 2020 (DRAFT)
Other Data Privacy Laws
- Prevention of Electronic Crimes Act (2016)
Active Legal Provisions
- Data Localization Provisions - Local Only
- Online Data Privacy Element
Encryption Policies
- Licensing/registration requirements
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Panama
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Law (2019)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Strategy for Cyber Security and Critical Infrastructure (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Authority for Government Innovation
International Commitments
- Member of the Budapest Convention (2014)
Paraguay
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Personal Credit Data Protection Law (2020)
- Electronic Commerce Law (2013)
Active Legal Provisions
- Data Localization Provisions - Conditional restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Plan: Challenges, Roles and Commitments (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Secretariat of Information and Communication Technologies (SENATICS)
International Commitments
- No Data
Peru
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Personal Data Protection Law No.29733 (2011)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Philippines
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Privacy Act of (2012)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Cybersecurity Provisions
- Breach Notification
Encryption Policies
- Mandatory minimum or maximum encryption strength
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Plan 2022 (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
National Cybersecurity Agency: Cybercrime Investigation and Coordination Center (CICC)
International Commitments
- No Data
Poland
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Act on the Protection of Personal Data 1997
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Strategy of the Republic of Poland, 2019-2024 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Ministry of Digital Affairs
International Commitments
- Member of the Budapest Convention (2015)
Portugal
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Lei da proteçao de dados pessoais 1991 (in Portuguese)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Data subjects are notified of surveillance by intelligence services
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Strategy for Cyberspace Security 2019-2023 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Cyber Security Centre Portugal
International Commitments
- Member of the Budapest Convention (2010)
Qatar
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law No. (13) of 2016 Concerning Personal Data Protection (2016)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Cybersecurity Provisions
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Committee
International Commitments
- No Data
Romania
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Law on the Protection of Individuals with Regard to the Processing of Personal Data (2001)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Security Strategy of Romania (2013)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Cyber Security Operative Council
International Commitments
- Member of the Budapest Convention (2004)
- UN GGE 2019/2021 member
Russia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act No. 152 (2006/2014)
Other Data Privacy Laws
- Information, Information Technologies and Information Protection Act No. 149 (2006)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- Licensing/registration requirements
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Doctrine of Information Security (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Security Council of the Russian Federation
International Commitments
- UN GGE 2019/2021 member
Rwanda
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Policy (2015)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Authority (NCSA)
International Commitments
- Member of the Budapest Convention (2005)
Saint Lucia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Act 2011 (2011)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Samoa
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Samoa National Cybersecurity Strategy 2016-2021 (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National ICT Steering Committee
International Commitments
- No Data
Saudi Arabia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2020)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: National Cybersecurity Authority (NCA)
International Commitments
- No Data
Senegal
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Act (Loi No. 2008-12 du 25 janvier 2008 sur la protection des données à caractère personnel) (2008)
Other Data Privacy Laws
- Information, Information Technologies and Information Protection Act No. 149 (2006)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Enforcement Through Fine
Encryption Policies
- General right to encryption
- Mandatory minimum or maximum encryption strength
- Licensing/registration requirements
- Import/export controls
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2022 (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of the Digital Economy and Telecommunications
International Commitments
- Member of the Budapest Convention (2017)
Serbia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Law (2008/2018)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Strategy for the Development of Information Security in the Republic of Serbia for the period 2017-2020 (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Information and Communications Technologies Department
International Commitments
- Member of the Budapest Convention (2009)
Singapore
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Personal Data Protection Act (2012)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Enforcement Through Fine
Encryption Policies
- Import/export controls
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Singapore's Cybersecurity Strategy (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: The Cyber Security Agency of Singapore (CSA)
International Commitments
- UN GGE 2019/2021 member
Slovenia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Personal Data Protection Act 1990
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cyber Security Strategy (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Information Security Administration (ISARS)
International Commitments
- Member of the Budapest Convention (2005)
Slovakia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Act on the Protection of Personal Data 1992
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
The National Cybersecurity Strategy 2021-2025 (2021)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Security Authority
International Commitments
- Member of the Budapest Convention (2008)
South Africa
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Protection of Personal Information Act 4 (2013)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data localization provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Licensing/registration requirements
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Policy Framework for South Africa (2015)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: State Security Agency
International Commitments
- UN GGE 2019/2021 member
South Korea
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Personal Information Protection Act (2011)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects are notified of surveillance by intelligence services
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Center
International Commitments
- No Data
Spain
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Organic Law 15/1999 on Personal Data Protection
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- There are public cases of national intelligence services violating surveillance laws
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cybersecurity Council
International Commitments
- Member of the Budapest Convention (2010)
Sri Lanka
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Act to Provide for the Regulation of Processing of Personal Data (DRAFT)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Information and Cyber Security Strategy of Sri Lanka (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Sri Lanka Computer Emergency Readiness Team – Coordination Centre (Sri Lanka CERT|CC)
International Commitments
- Member of the Budapest Convention (2015)
Sweden
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- General Data Protection Regulation (GDPR) (2018)
Other Data Privacy Laws
- Personal Data Act 1998
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- There are public cases of national intelligence services violating surveillance laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
A National Cyber Security Strategy (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Swedish Civil Contingencies Agency (MSB)
International Commitments
- Member of the Budapest Convention (2021)
Switzerland
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Federal Act on Data Protection (1992/2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Strategy for the Protection of Switzerland Against Cyber Risks 2018-2022 (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Centre (NCSC)
International Commitments
- Member of the Budapest Convention (2012)
- UN GGE 2019/2021 member
Syria
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- Licensing/registration requirements
- Obligations on providers to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Information Security Policy (2014)
National Cybersecurity Agency: National Agency for Network Services (NANS)
International Commitments
- No Data
Taiwan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Law (2010/2015)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Facial recognition
- Japanese tech
Government Data Collection Laws
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Program of Taiwan (2021)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Department of Cyber Security & National Center for Cyber Security Technology
International Commitments
- No Data
Tajikistan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Law, No.1537 (2018)
Other Data Privacy Laws
- Protection Data Law, No. 631 (2002)
- Informatization Law, No. 40 (2001)
- Information Law, No. 609 (2002)
Active Legal Provisions
- Cybersecurity Provisions
- Enforcement Through Fine
- National Data Protection Authority
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Concept of Information Security of the Republic of Tajikistan (2003)
- Capacity-building to detect/respond to cyber threats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Centre of Information-Communication Technologies
International Commitments
- No Data
Thailand
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Personal Data Protection Act (2011/2019)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- Companies can challenge orders to provide personal data to law enforcement authorities
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Strategy 2017-2021 (2017)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Digital Economy and Society (MDES)
International Commitments
- No Data
Trinidad and Tobago
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection Act (2011)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy (2012)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of National Security
International Commitments
- No Data
Tunisia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law No.2004-63 on the Protection of Personal Data (2004/2016)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
Encryption Policies
- Licensing/registration requirements
- Import/export controls
- Other restrictions
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cybersecurity Agency: National Agency for Computer Security (ANSI)
International Commitments
- No Data
Turkey
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law on the Protection of Personal Data No. 6698 (2016)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy 2016-2019 (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Transport and Infrastructure
International Commitments
- Member of the Budapest Convention (2015)
Turkmenistan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law of Turkmenistan No. 519-V "On Information about Private Life and Its Protection" (2017)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- Data Localization Provisions - Local Copy
- Cybersecurity Provisions
- Online Data Privacy Element
Encryption Policies
- No Data
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
UAE
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Data Protection (Amendment) Regulation (2018)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Other restrictions
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy 2019 (2019)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Telecommunications Regulatory Authority
International Commitments
- No Data
Uganda
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection and Privacy Act (2015)
Other Data Privacy Laws
- Access to Information Act (2005)
- Regulation of Interception of Communications Act (2010)
- Computer Misuse Act (2011)
- Registration of Persons Act, 2015
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Information Security Policy (2014)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
National Cybersecurity Agency: National Information Technology Authority-Uganda (NITA-U)
International Commitments
- No Data
Ukraine
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- The Law of Ukraine No. 2297 VI "On Personal Data Protection" (2010/2013)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
- U.S. tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Cybersecurity Strategy (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Coordination Center for Cybersecurity
International Commitments
- Member of the Budapest Convention (2006)
United Kingdom
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- UK General Data Protection Regulation (UK GDPR) (2018/2019)
Other Data Privacy Laws
- Data Protection Act 2018
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
National Cyber Security Strategy 2016-2021 (2016)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: National Cyber Security Centre (NCSC)
International Commitments
- Member of the Budapest Convention (2011)
- UN GGE 2019/2021 member
United States
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Privacy Act of 1974 (Does Not Include Provisions Related to Online Privacy)
- State Laws
Active Legal Provisions
- No Data
Encryption Policies
- Import/export controls
- Obligations on providers to assist authorities
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Data subjects have the right to court review of surveillance measures taken by intelligence services
- Companies can challenge orders to provide personal data to law enforcement authorities
- Intelligence services can compel companies to provide access to data
- There are public cases of national intelligence services violating surveillance laws
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
White House National Cyber Strategy (2018) & Department of Homeland Security Cybersecurity Strategy (2018)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
National Cybersecurity Agency: Cybersecurity and Infrastructure Security Agency (CISA)
International Commitments
- Member of the Budapest Convention (2007)
- UN GGE 2019/2021 member
Uruguay
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Act Law No. 18331 (2008)
Other Data Privacy Laws
- No Data
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Predictive policing
- Chinese tech
- U.S. tech
- Chinese tech
- U.S. tech
- Japanese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- UN GGE 2019/2021 member
Uzbekistan
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Law of the Republic of Uzbekistan No. ZRU-547 “On Personal Data” (2019)
Other Data Privacy Laws
- Law No. 439-II 'On Principles and Guarantees of Freedom of Information' (2002)
- Law No. 560-II 'On Informatization' (2003)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Localization Provisions - Conditional Restrictions
- Cybersecurity Provisions
- Enforcement Through Fine
Encryption Policies
- No Data
AI Surveillance
- Smart city
- Facial recognition
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- No Data
Vanuatu
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- No Data
Active Legal Provisions
- No Data
Encryption Policies
- General right to encryption
- Licensing/registration requirements
- Import/export controls
AI Surveillance
- No Data
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Vanuatu National Cyber Security Strategy (2021)
- Capacity-building to detect/respond to cyber threats
- Protection of critical infrastructure
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Office of the Government Chief Information Office
International Commitments
- No Data
Vietnam
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- No Data
Other Data Privacy Laws
- Cybersecurity Law (2013)
- Network Information Security Law (2018)
- Constitution (2013)
- Civil Code (2013)
- Law on Protection of Consumers' Rights (2010)
- Law on Information Technology (2006)
- E-transactions Law (2005)
Active Legal Provisions
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- Licensing/registration requirements
- Import/export controls
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
- Other restrictions
AI Surveillance
- No Data
Government Data Collection Laws
- Intelligence services operate surveillance programs to protect national security
- Intelligence services are authorized to conduct surveillance for economic purposes
- Intelligence services can compel companies to provide access to data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
Decision approving the orientation, objectives and duties to ensure the cyber information security for the period 2016-2020 (2016)
- Capacity-building to detect/respond to cyber threats
- Public education/awareness-raising about cyberthreats
- Commitment to develop cybersecurity research/industry
- Commitment to develop domestic regulatory/legal framework
National Cybersecurity Agency: Ministry of Information and Communications
International Commitments
- No Data
Zambia
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Data Protection Act No. 3 (2021)
Other Data Privacy Laws
- Electronic Communications and Transactions Act No. 4 (2021)
- Cyber Security and Cyber Crimes Act No. 2 (2021)
- Information and Communications Technologies Act No. 15 (2009)
Active Legal Provisions
- National Data Protection Authority
- Registration Requirement
- Data Protection Officers
- Data Localization Provisions - Local Only
- Cybersecurity Provisions
- Breach Notification
- Enforcement Through Fine
- Online Data Privacy Element
Encryption Policies
- General right to encryption
- Licensing/registration requirements
- Other restrictions
AI Surveillance
- Facial recognition
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- Member of the Budapest Convention (since 2013)
- UN GGE 2019/2021 member
Zimbabwe
Data Privacy Laws (Year Enacted/Updated)
Comprehensive Data Privacy Law
- Cybersecurity and Data Protection Bill of 2019 (DRAFT)
Other Data Privacy Laws
- Constitution of Zimbabwe Amendment 20 (2013)
- Freedom of Information Act (2020)
Active Legal Provisions
- No Data
Encryption Policies
- Obligations on providers to assist authorities
- Obligations on individuals to assist authorities
AI Surveillance
- Facial recognition
- Predictive policing
- Chinese tech
Government Data Collection Laws
- No Data
Cybersecurity Commitments (Year Adopted/Ratified)
Domestic Commitments
- No Data
International Commitments
- Member of the Budapest Convention (since 2013)
- UN GGE 2019/2021 member