Law/RegulationCountry/RegionHighlightsApplies to
PIPEDA (Personal Information Protection and Electronic Documents Act) CanadaGoverns how private-sector organizations collect, use, and disclose personal data in commercial activities Private-sector organizations
LGPD (Lei Geral de Proteção de Dados) BrazilBrazil’s equivalent to GDPR requires consent, breach notification, and DPOsAny organization handling the personal data of Brazilians
PDPA (Personal Data Protection Act)Singapore, Thailand, Malaysia Leading privacy laws in Southeast Asia focus on consent, access, and usage limitsBusinesses, public agencies, and data intermediaries
New Zealand Privacy Act 2020New ZealandIntroduces mandatory breach notifications and tighter cross-border data handling rulesGovernment and private-sector entities
PIPL (Personal Information Protection Law)ChinaOne of the most stringent laws, GDPR-like, but includes strict data localization and government oversightAll companies processing Chinese citizens’ data
POPIA (Protection of Personal Information Act)South AfricaEnsures data is processed lawfully and minimally while granting individuals access, correction, or deletion rights Public and private bodies handling personal information