Privacy laws
Compare privacy frameworks side by side
Pick two or three frameworks to see how they differ on scope, consent, rights, breach handling, transfers and enforcement. These are high-level orientation summaries, not a substitute for reading the law or taking advice.
| Dimension | EU GDPRNational supervisory authorities, coordinated by the European Data Protection BoardLast reviewed August 2026 | US state privacyCalifornia Privacy Protection Agency and state attorneys generalLast reviewed August 2026 |
|---|---|---|
| Who and what it covers | Establishment in the EU/EEA, or targeting/monitoring people in the EU/EEA. No size threshold. | Threshold-based per state: revenue, data volume, or revenue from selling/sharing personal information. |
| Lawful basis / consent approach | Six lawful bases; consent is one option. Additional conditions for special-category data. | No general lawful-basis model; notice plus opt-out, with opt-in or limit-use rules for sensitive data in some states. |
| Individual rights | Information, access, rectification, erasure, restriction, portability, objection, automated-decision safeguards. | Know/access, delete, correct, opt out of sale/share and targeted advertising, limit sensitive data use, appeal. |
| Breach handling | Notify the supervisory authority without undue delay and within 72 hours where feasible; notify individuals where risk is high. | State breach notification statutes with differing triggers, timing and content requirements. |
| Cross-border transfers | Adequacy, SCCs, BCRs or a derogation, with a transfer impact assessment where safeguards are used. | No general geographic transfer restriction; controlled contractually through service provider terms. |
| Regulator and enforcement | National supervisory authorities; fines up to the greater of EUR 20m or 4% of global annual turnover. | State attorneys general and, in California, the CPPA; per-violation penalties and a narrow breach private right of action. |
| Official sources |
Read these caveats. Every entry compresses a complex statute into a sentence. Scope tests, exemptions, sector rules and regulator guidance change the answer for specific organisations, and several of these frameworks have implementing rules that continue to develop.
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.
Share this result
The card below is everything that gets shared: the headline, the band and a few summary lines. Your individual answers, organisation name and any free text stay in your browser.
Nothing is posted automatically. Each button opens the network in a new tab with the text pre-filled so you can edit or cancel it.
Educational orientation only — not a compliance determination, audit or legal advice.
Embed this comparison
A read-only copy of the table above, for an intranet page or internal wiki. It loads no trackers and sets no cookies.
<iframe src="https://privacybuilt.com/privacy-laws/compare?laws=eu-gdpr,us-state-privacy&embed=1" title="EU GDPR vs US state privacy privacy law comparison" width="100%" height="720" loading="lazy" style="border:1px solid #e2e8f0;border-radius:12px"></iframe>