HOME

TheInfoList



OR:

Privacy law is a set of regulations that govern the collection, storage, and utilization of personal information from healthcare, governments, companies, public or private entities, or individuals. Privacy laws are examined in relation to an individual's entitlement to privacy or their reasonable expectations of privacy. The
Universal Declaration of Human Rights The Universal Declaration of Human Rights (UDHR) is an international document adopted by the United Nations General Assembly that enshrines the Human rights, rights and freedoms of all human beings. Drafted by a UN Drafting of the Universal D ...
asserts that every person possesses the right to privacy. However, the understanding and application of these rights differ among nations and are not consistently uniform. Throughout history, privacy laws have evolved to address emerging challenges, with significant milestones including the
Privacy Act of 1974 Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of ...
in the U.S. and the European Union's Data Protection Directive of 1995. Today, international standards like the
GDPR The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
set global benchmarks, while sector-specific regulations like
HIPAA The Health Insurance Portability and Accountability Act of 1996 (HIPAA or the Kennedy– Kassebaum Act) is a United States Act of Congress enacted by the 104th United States Congress and signed into law by President Bill Clinton on August 21, ...
and
COPPA Coppa or COPPA may refer to: * '' Coppa'' or ''capocollo'', a type of Italian pork cold cut * Montonico bianco, a white Italian wine grape variety grown in the Calabria region of southern Italy * Coppa (surname) * Coppa Italia, a domestic Italian l ...
complement state-level laws in the U.S. In Canada,
PIPEDA The ''Personal Information Protection and Electronic Documents Act'' (PIPEDA; ) is a Canadian law relating to data privacy. It governs how private sector organizations collect, use and disclose personal information in the course of commercial bu ...
governs privacy, with recent case law shaping privacy rights. Digital platform challenges underscore the ongoing evolution and compliance complexities in privacy law.


Classification of privacy laws

Privacy laws can be broadly classified into: * Privacy * Trespassing * Negligence * Fiduciary The categorization of different laws involving individual rights of privacy assesses how different laws protect individuals from being having their rights of privacy violated or abused by certain groups or persons. These classifications provide a framework for understanding the legal principles and obligations that check privacy protection and enforcement efforts and for policymakers, legal practitioners, and individuals to better understand the complexity of the responsibilities involved in order to ensure the protection of privacy rights. Brief overview of the 4 classifications of each category to understand the ways in which privacy rights are protected and regulated: Privacy Laws focus on protecting individuals’ rights to control their personal information and prevent unauthorized intrusion into their private lives. They encompass strict regulations governing data protection, confidentiality, surveillance, and the use of personal information by both government and corporate entities. Trespassing Laws focus on breaches of privacy rights related to physical intrusion onto an individual's property or personal domain without consent. This involves illegal activities such as: entering an individual’s residence without consent, conducting surveillance using physical methods (e.g., deploying hidden cameras), or any unauthorized entry onto the individual’s property. Negligence laws generally address situations where individuals or entities fail to exercise appropriate caution in protecting the privacy rights of others, often holding them accountable through severe penalties like heavy fines. This aims to ensure compliance and deter future violations, involving incidents such as any mishandling of sensitive data, poor security measures leading to data breaches, or any non-compliance with privacy policies and regulations. Fiduciary laws regulate the relationships characterized by trust and confidence, where the fiduciary accepts and complies with the legal responsibility for duties of care, loyalty, good faith, confidentiality, and more when entrusted in serving the best interests of a beneficiary. In terms of privacy, fiduciary obligations may extend to professionals like lawyers, doctors, financial advisors, and others responsible for handling confidential information, as a result of a duty of confidentiality to their clients or patients.


Data Protection Laws in the United States

* Children's Online Privacy Protection Act: provides data protection requirements for children's information collected by online operators. * Communications Act of 1934: includes data protection provisions for common carriers, cable operators, and satellite carriers. * Computer Fraud and Abuse Act: prohibits the unauthorized access of protected computers. * Consumer Financial Protection Act: regulates unfair, deceptive, or abusive acts in connection with consumer financial products or services. * Electronic Communications Privacy Act: prohibits the unauthorized access or interception of electronic communications in storage or transit. * Fair Credit Reporting Act: covers the collection and use of data contained in consumer reports. * Federal Securities Laws: may require data security controls and data breach reporting responsibilities. * Federal Trade Commission Act: prohibits unfair or deceptive acts or practices. * Gramm-Leach-Bliley Act: regulates financial institutions' use of nonpublic personal information. * Health Insurance Portability and Accountability Act: regulates health care providers' collection and disclosure of protected health information. * Video Privacy Protection Act: provides privacy protections related to video rental and streaming.


International legal standards on privacy


Asia-Pacific Economic Cooperation

The
Asia-Pacific Economic Cooperation Asia-Pacific Economic Cooperation (APEC ) is an inter-governmental forum for 21 member economy , economies in the Pacific Rim that promotes free trade throughout the Asia-Pacific region. Following the success of Association of Southeast Asia ...
(APEC) introduced a voluntary Privacy Framework in 2004, which all 21 member economies adopted. This framework aims to enhance general information privacy and facilitate the secure transfer of data across borders. It comprises nine Privacy Principles, serving as minimum standards for privacy protection, including measures to prevent harm, provide notice, limit data collection, ensure personal information is used appropriately, offer choice to individuals, maintain data integrity, implement security safeguards, allow access and correction of personal information, and enforce accountability. In 2011, APEC established the APEC Cross Border Privacy Rules System to balance the flow of information and data across borders, which is crucial for fostering trust and confidence in the online marketplace. This system builds upon the APEC Privacy Framework and incorporates four agreed-upon rules, which involve self-assessment, compliance review, recognition/acceptance, and dispute resolution and enforcement.


Council of Europe

Article 8 of the
European Convention on Human Rights The European Convention on Human Rights (ECHR; formally the Convention for the Protection of Human Rights and Fundamental Freedoms) is a Supranational law, supranational convention to protect human rights and political freedoms in Europe. Draf ...
, established by the
Council of Europe The Council of Europe (CoE; , CdE) is an international organisation with the goal of upholding human rights, democracy and the Law in Europe, rule of law in Europe. Founded in 1949, it is Europe's oldest intergovernmental organisation, represe ...
in 1950 and applicable across the European continent except for Belarus and Kosovo, safeguards the right to privacy. It asserts that "Everyone has the right to respect for his private and family life, his home and his correspondence." Through extensive case law from the European Court of Human Rights in Strasbourg, privacy has been clearly defined and universally recognized as a fundamental right. Furthermore, the Council of Europe took steps to protect individuals' privacy rights with specific measures. In 1981, it adopted the Convention for the protection of individuals with regard to automatic processing of personal data. Additionally, in 1998, the Council addressed privacy concerns related to the internet by publishing "Draft Guidelines for the protection of individuals with regard to the collection and processing of personal data on the information highway," developed in collaboration with the European Commission. These guidelines were formally adopted in 1999.


European Union (EU)

The 1995
Data Protection Directive The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, was a European Union directive which regulated the processing of personal data within the European Union (EU) and the free movement of such data. The Data ...
(officially Directive 95/46/EC) acknowledged the authority of National data protection authorities and mandated that all Member States adhere to standardized privacy protection guidelines. These guidelines stipulated that Member States must enact stringent privacy laws consistent with the framework provided by the Directive. Moreover, the Directive specified that non-EU countries must implement privacy legislation of equivalent rigor to exchange personal data with EU countries. Additionally, companies in non-EU countries wishing to conduct business with EU-based companies must adhere to privacy standards at least as strict as those outlined in the Directive. Consequently, the Directive has influenced the development of privacy legislation beyond European borders. The proposed ePrivacy Regulation, intended to replace the Privacy and Electronic Communications Directive 2002, further contributes to EU privacy regulations. On 25 May 2018, the
General Data Protection Regulation The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
superseded the Data Protection Directive of 1995. A significant aspect introduced by the General Data Protection Regulation is the recognition of the "right to be forgotten," which mandates that any organization collecting data on individuals must delete the relevant data upon the individual's request. The Regulation drew inspiration from the European Convention on Human Rights mentioned earlier.


Organization for Economic Co-operation and Development (OECD)

The
OECD The Organisation for Economic Co-operation and Development (OECD; , OCDE) is an international organization, intergovernmental organization with 38 member countries, founded in 1961 to stimulate economic progress and international trade, wor ...
(Organisation for Economic Co-operation and Development) initiated privacy guidelines in 1980, setting international standards, and in 2007, proposed cross-border cooperation for privacy law enforcement. The UN's
International Covenant on Civil and Political Rights The International Covenant on Civil and Political Rights (ICCPR) is a multilateral treaty that commits nations to respect the civil and political rights of individuals, including the right to life, freedom of religion, freedom of speech, freedom ...
, Article 17, protects privacy, echoed in the 2013 UN General Assembly resolution affirming privacy as a fundamental human right in the digital age. The Principles on Personal Data Protection and Privacy for the UN System were declared in 2018.


United Nations (UN)

Article 17 of the
International Covenant on Civil and Political Rights The International Covenant on Civil and Political Rights (ICCPR) is a multilateral treaty that commits nations to respect the civil and political rights of individuals, including the right to life, freedom of religion, freedom of speech, freedom ...
of the United Nations in 1966 also protects privacy: "No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks." On 18 December 2013, the United Nations General Assembly adopted resolution 68/167 on the right to privacy in the digital age. The resolution makes reference to the Universal Declaration of Human Rights and reaffirms the fundamental and protected human right of privacy. The Principles on Personal Data Protection and Privacy for the United Nations System were declared on 11 October 2018.


Privacy laws by country


Australia

The current state of privacy law in Australia includes Federal and state information privacy legislation, some sector-specific privacy legislation at state level, regulation of the media and some criminal sanctions. The current position concerning civil causes of action for invasion of privacy is unclear: some courts have indicated that a tort of invasion of privacy may exist in Australia.. However this has not been upheld by the higher courts, which have been content to develop the equitable doctrine of Breach of Confidence to protect privacy, following the example set by the UK. In 2008, the
Australian Law Reform Commission The Australian Law Reform Commission (often abbreviated to ALRC) is an Australian independent statutory body established to conduct reviews into the law of Australia. The reviews, also called inquiries or references, are referred to the ALRC by ...
recommended the enactment of a statutory cause of action for invasion of privacy."Invasion of privacy: penalties and remedies: review of the law of privacy: stage 3" (2009) (Issues paper 14), New Zealand Law Commission, , 2009 NZIP 14 accessed 27 August 2011 The
Privacy Act 1988 The ''Privacy Act 1988'' is an Australian law dealing with privacy. Section 14 of the Act stipulates a number of privacy rights known as the Australian Privacy Principles (APPs). These principles apply to Australian Government and Australian C ...
aims to protect and regulate an individual's private information. It manages and monitors
Australian Government The Australian Government, also known as the Commonwealth Government or simply as the federal government, is the national executive government of Australia, a federal parliamentary constitutional monarchy. The executive consists of the pr ...
and organisations on how they hold personal information.


Bahamas

The Bahamas has an official data protection law that protects the personal information of its citizens in both the private and public sector: Data Protection Act 2003 (the Bahamas Law). The Bahamas Law appoints a data protection commissioner to the Office of Data Protection to ensure that data protection is being held. Even though there is legislation enforced in the Bahamas through the Data Protection Act 2003, the act lacks many enforcements since a data protection officer doesn't need to be in office nor does any group or organization need to notify the Office of Data Protection when a hacker has breached privacy law. Also, there are no requirements for registering databases or restricting data flow across national borders. Therefore, the legislation does not meet European Union standards, which was the goal of creating the law in the first place. The Bahamas is also a member of CARICOM, the Caribbean Community.


Belize

Belize is currently part of the minority of countries that do not have any official data privacy laws.Greenleaf, Graham. 2015. "Global Data Privacy Laws 2015: 109 Countries, with European Laws Now a Minority"''.'' ''Privacy Laws & Business International Report'' 21. However, the
Freedom of Information Act Freedom of Information Act may refer to the following legislations in different jurisdictions which mandate the national government to disclose certain data to the general public upon request: * Freedom of Information Act (United States) of 1966 * F ...
(2000) currently protects the personal information of the citizens of Belize, but there is no current documentation that distinguishes if this act includes electronic data. As a consequence of the lack of official data privacy laws, there was a breach of personal data in 2009 when an employee's laptop from Belize's Vital Statistics Unit was stolen, containing birth certification information for all citizens residing in Belize. Even though the robbery was not intentionally targeting the laptop - the robber did not predict the severity of the theft - Belize was put in a vulnerable position which could have been avoided if regulations were in order.


Brazil

A Brazilian citizen's privacy is protected by the country's constitution, which states: On 14 August 2018, Brazil enacted its
General Personal Data Protection Law The General Personal Data Protection Law (, or LGPD; Lei 13709/2018), is a statutory law on data protection and privacy in the Federative Republic of Brazil. The law's primary aim is to unify 40 different Brazilian laws that regulate the processi ...
. The bill has 65 articles and has many similarities to the GDPR. The first translation into English of the new data protection law was published by
Ronaldo Lemos Ronaldo Lemos (Araguari, born March 25, 1976) is a Brazilian academic, lawyer and commentator on intellectual property, technology, and culture. Lemos is the director of the Institute for Technology & Society of Rio de Janeiro (ITSrio.org), and ...
, a Brazilian lawyer specialized in technology, on that same date. There is a newer version.


Canada

In Canada, the federal ''
Personal Information Protection and Electronic Documents Act The ''Personal Information Protection and Electronic Documents Act'' (PIPEDA; ) is a Canadian law relating to data privacy. It governs how private sector organizations collect, use and disclose personal information in the course of commercial bu ...
'' (PIPEDA) governs the collection, use, and disclosure of personal information in connection with commercial activities, as well as personal information about employees of federal works, undertakings and businesses. The PIPEDA brings Canada into compliance with EU data protection law, although civil society, regulators, and academics have more recently claimed that it does not address modern challenges of privacy law sufficiently, particularly in view of AI, calling for reform. PIPEDA does not apply to non-commercial organizations or provincial governments, which remain within the jurisdiction of provinces. Five Canadian provinces have enacted privacy laws that apply to their private sector. Personal information collected, used and disclosed by the federal government and crown corporations is governed by the '' Privacy Act''. Many provinces have enacted provincial legislation similar to the Privacy Act, such as the Ontario '' Freedom of Information and Protection of Privacy Act'' which applies to public bodies in that province. There remains some debate whether there exists a common law tort for breach of privacy across Canada. There have been a number of cases identifying a common law right to privacy but the requirements have not always been articulated clearly. In ''Eastmond v. Canadian Pacific Railway & Privacy Commissioner of Canada''''Eastmond v. Canadian western Railway & Privacy Commissioner of Canada'', 11 June 2004
Canada's Supreme Court Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, making it the world's second-largest country by total area, with the ...
found that CP could collect Eastmond's personal information without his knowledge or consent because it benefited from the exemption in paragraph 7(1)(b) of
PIPEDA The ''Personal Information Protection and Electronic Documents Act'' (PIPEDA; ) is a Canadian law relating to data privacy. It governs how private sector organizations collect, use and disclose personal information in the course of commercial bu ...
, which provides that personal information can be collected without consent if "it is reasonable to expect that the collection with the knowledge or consent of the individual would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement".


Implications for Specific Sectors

Canadian privacy laws have significant implications for various sectors, particularly finance, healthcare, and digital commerce. For instance, the financial sector is strictly regulated under
PIPEDA The ''Personal Information Protection and Electronic Documents Act'' (PIPEDA; ) is a Canadian law relating to data privacy. It governs how private sector organizations collect, use and disclose personal information in the course of commercial bu ...
, which requires financial institutions to obtain consent for the collection, use, or disclosure of personal information. Moreover, these institutions must also provide robust safeguards to protect this information against loss or theft. In healthcare, provinces like Alberta and British Columbia have specific laws protecting personal health information, which require healthcare providers to manage patient data with high confidentiality and security levels. This includes ensuring that patient consent is obtained before their personal health information is shared or accessed.


Case Law and Regulatory Actions

Recent case law in Canada has further defined the scope and application of privacy laws. For instance, the case of ''Jones v. Tsige'' recognized the tort of intrusion upon seclusion, affirming that individuals have a right to privacy against unreasonable intrusion. This landmark ruling has significant implications for how personal data is handled across all sectors, emphasizing the need for businesses to maintain strict privacy controls.


Interaction with International Privacy Frameworks

Canadian privacy laws also interact with international frameworks, notably the European Union’s General Data Protection Regulation (GDPR). Although PIPEDA shares many similarities with GDPR, there are nuanced differences, particularly in terms of consent and data subject rights. Canadian businesses dealing with international data need to comply with both PIPEDA and GDPR, making compliance a complex but critical task


Privacy Rights and Obligations in Digital Platforms

The digital transformation has brought specific challenges and focus areas for privacy regulation in Canada. The Canadian Anti-Spam Legislation (CASL), for example, regulates how businesses can conduct digital marketing and communications, requiring explicit consent for sending commercial electronic messages. This legislation is part of Canada's efforts to protect consumers from spam and related threats while ensuring that businesses conduct their digital marketing responsibly. The rise of digital platforms has also prompted discussions about privacy rights concerning consumer data collected by large tech companies. The Privacy Commissioner of Canada has been active in investigating and regulating how these companies comply with Canadian privacy laws, ensuring they provide transparency to users about data usage and uphold the rights of Canadian citizens


Future Directions and Compliance Challenges

Canadian privacy laws are continually evolving to address new challenges posed by technological advancements and global data flows. Businesses operating in Canada must stay informed about these changes to ensure compliance and protect the personal information of their customers effectively. For detailed guidance and the latest updates on compliance with Canadian privacy laws, businesses and individuals can refer to resources provided by the Office of the Privacy Commissioner of Canada and stay informed about developments in Canadian privacy law through expert analyses and updates.


China

In 1995, the Computer Processed Personal Information Protection Act was enacted in order to protect personal information processed by computers. The general provision specified the purpose of the law, defined crucial terms, prohibited individuals from waiving certain rights. The National Security Law and the Cybersecurity Law promulgated in 2015 give public security and security departments great powers to collect all kinds of information, forcing individuals to use network services to submit private information for monitoring, and forcing network operators to store user data Within China, unrestricted "technical support" from the security department must be provided. Other laws and regulations related to privacy are as follows:


Constitution

Article 38. The personal dignity of citizens of the People's Republic of China shall not be violated. It is forbidden to use any method to insult, slander, and falsely accuse citizens. Article 39. The residences of the People's Republic of China should be inviolable. It is prohibited to illegally search or trespass into citizens’ houses. Article 40. The freedom and confidentiality of communications of citizens of the People’s Republic of China are protected by law. Except for the needs of national security or the pursuit of criminal offenses, the public security organs or procuratorial organs shall inspect communications in accordance with the procedures prescribed by law, no organization or individual may infringe on citizens’ freedom of communication and confidentiality for any reason.


Civil Code

Article 1032. Natural persons enjoy the right to privacy. No organization or individual may infringe the privacy rights of others by spying, harassing, divulging, disclosing, etc.


Privacy of the deceased

The Supreme People's Court's "Interpretation on Several Issues Concerning the Determination of Liability for Compensation for Mental Damage in Civil Torts" was adopted at the 116th meeting of the Judicial Committee of the Supreme People's Court on February 26, 2001. Article 3 After the death of a natural person, if a close relative of a natural person suffers mental pain due to the following infringements, and the people’s court sues for compensation for mental damage, the people’s court shall accept the case: (2) Illegal disclosure or use of the privacy of the deceased, or infringement of the privacy of the deceased in other ways that violate social public interests or social ethics.


Law on the Protection of Minors

Article 39. No organization or individual may disclose the personal privacy of minors. No organization or individual may conceal or destroy letters, diaries, and e-mails of minors, except for the need to investigate crimes. Public security organs or people's procuratorates shall conduct inspections in accordance with the law, or letters, diaries, and e-mails of minors who are incapacitated. Diaries and e-mails shall be opened and read by their parents or other guardians, and no organization or individual shall open or read them.


Fiji

An archipelago located in the Pacific, the country of
Fiji Fiji, officially the Republic of Fiji, is an island country in Melanesia, part of Oceania in the South Pacific Ocean. It lies about north-northeast of New Zealand. Fiji consists of an archipelago of more than 330 islands—of which about ...
was founded on 10 October 1970."Constitution of the Republic of Fiji." The Fijian Government — Department of Information. Retrieved 1 May 2017. In its constitution, the people inhabiting the land are granted the right to
privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
. The exact workings from the constitution is the following: "Every person has the right to personal privacy, which includes the right to — (a)
confidentiality Confidentiality involves a set of rules or a promise sometimes executed through confidentiality agreements that limits the access to or places restrictions on the distribution of certain types of information. Legal confidentiality By law, la ...
of their personal information; (b) confidentiality of their communications; and (c) respect for their private and family life". But in this very same constitution, it is expressed that it is possible "to the extent that it is necessary" for a law to be passed that limits or impacts the execution of the right to privacy law. Another privacy related law can be seen in section 54 of the Telecommunications Promulgation passed in 2008, which states that "any service provider supplying telecommunications to consumers must keep information about consumers confidential". Billing information and call information are no exceptions. The only exception to this rule is for the purpose of bringing to light "fraud or bad debt". Under this law, even with the consent of the customer, the disclosure of information is not permitted. Other Privacy laws that have been adopted by this country are those that are meant to protect the collected information, cookies and other privacy-related matter of tourist. This is in regards to (but not limited to) information collected during bookings, the use of one technology of another that belongs to said company or through the use of a
service Service may refer to: Activities * Administrative service, a required part of the workload of university faculty * Civil service, the body of employees of a government * Community service, volunteer service for the benefit of a community or a ...
of the company, or when making
payment A payment is the tender of something of value, such as money or its equivalent, by one party (such as a person or company) to another in exchange for goods or services provided by them, or to fulfill a legal obligation or philanthropy desir ...
s. Additionally, as a member of the United Nations, the Fiji is bound by the Universal Declaration of Human Rights which states in article twelve, "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


France

France adopted a data privacy law in 1978. It applies to public and private organizations and forbids gathering sensitive data about physical persons (including sexuality, ethnicity, and political or religious opinions). The law is administered by the Commission nationale de l'informatique et des libertés (CNIL), a dedicated national administration. Like in Germany, data violations are considered criminal offenses (Art. 84 GPR with Code Pénal, Section 1, Chapitre VI, Art. 226ff.).


Germany

Germany is known to be one of the first countries (in 1970) with the strictest and most detailed data privacy laws in the world. The citizens' right to protection is stated in the Constitution of Germany, in Art. 2 para. 1, and Art. 1 para. 1. The citizens' data of Germany is mainly protected under the Federal Data Protection Act (1977) from corporations, which has been amended the most recently in 2009. This act specifically targets all businesses that collect information for its use. The major regulation protects the data within the private and personal sector, and as a member of the European Union (EU), Germany has additionally ratified its act, convention, and additional protocol with the EU according to the EU Data Protection Directive 95/46 EC. In Germany, there are two kinds of restrictions on a transfer of personal data. Since Germany is part of the EU Member States, the transfer of personal data of its citizens to a nation outside the EEA is always subject to a decent level of data protection in the offshore country. Secondly, according to German data policy rules, any transfer of personal data outside the EEA symbolizes a connection to a third party which requires a reason. That reason may be for emergency reasons, and a provision must be met with consent by the receiver and the subject of the data. Keep in mind that in Germany, data transfers within a group of companies is subject to the same treatment as transfer to third-parties if the location is outside the EEA. Specifically, the Federal Data Protection Commission is in charge of regulating the entirety of the enforcement of data privacy regulations for Germany. In addition, Germany is part of the Organisation for Economic Cooperation and Development (OECD).Western Hemisphere Data Protection Laws. 2012. U.S. Department of Commerce. http://web.ita.doc.gov/ITI/itiHome.nsf/9b2cb14bda00318585256cc40068ca69/a54f62c93fd1572985257623006e32d5/$FILE/Western%20Hemisphere%20Data%20Protection%20Laws%205-12%20final.pdf The Federal Data Protection Commission of Germany is a member of the International Conference of Data Protection and Privacy Commissioners, European Data Protection Authorities, the EU Article 29 Working Party, and the Global Privacy Enforcement Network. Regarding the protection of children, Germany is potentially the first nation that has played an active role in banning the share of data within toys connected to Wi-Fi and the Internet, like for instance, "My Friend Cayla". The group in charge of protecting the data of children is the
Federal Network Agency The Federal Network Agency ( or ) is the German regulatory office for electricity, gas, telecommunications, post and railway markets. It is a federal agency of the Federal Ministry for Economic Affairs and Climate Action and headquartered in Bo ...
(''Bundesnetzagentur'').  Like in France, data violations are considered offenses (Art. 84 GPR with § 42 BDSG).


Greece

During the military dictatorship era the 57 AK law prohibited taking photos of people without their permission but the law has since been superseded. The 2472/1997 law protects personal data of citizens but consent for taking photos of people is not required as long as they aren't used commercially or are used only for personal archiving ("οικιακή χρήση" / "home use"), for publication in editorial, educational, cultural, scientific or news publications, and for fine art purposes (e.g.
street photography Street photography is photography conducted for art or inquiry that features unmediated chance encounters and random incidents within Public space, public places. It usually has the aim of capturing images at a decisive or poignant moment by caref ...
which has been uphold as legal by the courts whether done by professional or amateur photographers). However, photographing people or collecting their personal data for commercial (advertising) purposes requires their consent. The law gives photographers the right to commercially use photos of people who have not consented to the use of the images in which they appear if the depicted people have either been paid for the photo session as models (so there is no separation between editorial and commercial models in Greek law) or they have paid the photographer for obtaining the photo (this, for example, gives the right to wedding photographers to advertise their work using their photos of newly-wed couples they photographed in a professional capacity). In Greece the right to take photographs and publish them or sell licensing rights over them as fine art or editorial content is protected by the
Constitution of Greece The Constitution of Greece () was created by the Fifth Revisionary Hellenic Parliament in 1974, after the fall of the Greek junta and the start of the Third Hellenic Republic. It came into force on 11 June 1975 (adopted two days prior) and has ...
(Article 14 and other articles) and free speech laws as well as by
case law Case law, also used interchangeably with common law, is a law that is based on precedents, that is the judicial decisions from previous cases, rather than law based on constitutions, statutes, or regulations. Case law uses the detailed facts of ...
and legal cases. Photographing the police or children and publishing the photographs in a non-commercial capacity is also legal.


Hong Kong

In Hong Kong, the law governing the protection of personal data is principally found in the Personal Data (Privacy) Ordinance (Cap. 486) which came into force on 20 December 1996. Various amendments were made to enhance the protection of personal data privacy of individuals through the Personal Data (Privacy) (Amendment) Ordinance 2012. Examples of personal data protected include names, phone numbers, addresses, identity card numbers, photos, medical records and employment records. As Hong Kong remains a common law jurisdiction, judicial cases are also a source of privacy law. The power of enforcement is vested with the Privacy Commissioner (the "Commissioner") for Personal Data. Non-compliance with data protection principles set out in the ordinances does not constitute a criminal offense directly. The Commissioner may serve an enforcement notice to direct the data user to remedy the contravention and/or instigate the prosecution action. Contravention of an enforcement notice may result in a fine and imprisonment.


India

India's data protection law is known as The
Digital Personal Data Protection Act, 2023 The Digital Personal Data Protection Act, 2023 (also known as DPDP Act or DPDPA-2023) is an act of the Parliament of India to provide for the processing of digital personal data in a manner that recognises both the right of individuals to prote ...
, the Right to Privacy is a
fundamental right Fundamental rights are a group of rights that have been recognized by a high degree of protection from encroachment. These rights are specifically identified in a constitution, or have been found under due process of law. The United Nations' Susta ...
and an intrinsic part of Article 21 that protects life and liberty of the citizens and as a part of the freedoms guaranteed by Part III of the
Constitution A constitution is the aggregate of fundamental principles or established precedents that constitute the legal basis of a polity, organization or other type of entity, and commonly determines how that entity is to be governed. When these pri ...
. In June 2011, India passe
subordinate legislation
that included various new rules that apply to companies and consumers. A key aspect of the new rules required that any organization that processes personal information must obtain written consent from the data subjects before undertaking certain activities. However, application and enforcement of the rules is still uncertain. The Aadhaar Card privacy issue became controversial when the case reached the Supreme Court. The hearing in the
Aadhaar Aadhaar (Hindi: आधार, ) is a twelve-digit unique identity number that can be obtained voluntarily by all residents of India, based on their biometrics and demography, demographic data. The data is collected by the Unique Identification ...
case went on for 38 days across 4 months, making it the second longest Supreme Court hearing after the landmark Kesavananda Bharati v. State of Kerala. On 24 August 2017, a nine-judge bench of the Supreme Court in Justice K. S. Puttaswamy (Retd.) and Anr. vs Union Of India And Ors. unanimously held that the right to privacy is an intrinsic part of right to life and personal liberty under Article 21 of the Constitution. Previously, the Information Technology (Amendment) Act, 2008 made changes to the
Information Technology Act, 2000 The Information Technology Act, 2000 (also known as ITA-2000, or the IT Act) is an Act of the Indian Parliament (No 21 of 2000) notified on 17 October 2000. It is the primary law in India dealing with cybercrime and electronic commerce. Secon ...
and added the following two sections relating to Privacy: * Section 43A, which deals with implementation of ''reasonable security practices'' for ''sensitive personal data or information'' and provides for the compensation of the person affected by ''wrongful loss or wrongful gain''. * Section 72A, which provides for imprisonment for a period up to three years and/or a fine up to Rs. for a person who causes ''wrongful loss or wrongful gain'' by disclosing personal information of another person while ''providing services under the terms of lawful contract''. A constitutional bench of the Supreme Court declared 'Privacy' as a fundamental right on 24 August 2017.


Ireland

Ireland is under the Data Protection Act 1988 along with the EU
General Data Protection Regulation The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
, which regulates the utilization of personal data. The DPA protects data within the private and personal sector. The DPA ensures that when data is transported, the location must be safe and in acknowledgement of the legislation to maintain
data privacy Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, contextual information norms, and the legal and political issues surrounding them. It is also known as data ...
. When collecting and processing data, some of the requirements are listed below: * the subject of personal data must have given
consent Consent occurs when one person voluntarily agrees to the proposal or desires of another. It is a term of common speech, with specific definitions used in such fields as the law, medicine, research, and sexual consent. Consent as understood i ...
* the data is in the subject's interest * the reason for the processing of data is for a contract * the reason for the processing of data is the prevention of injury Specifically the
Data Protection Commissioner The Office of the Data Protection Commissioner () (DPC), also known as Data Protection Commission, is the independent national authority responsible for upholding the EU fundamental right of individuals to data privacy through the enforcement ...
oversees the entirety of the enforcement of data privacy regulations for Ireland. All persons that collect and process data must register with the Data Protection Commissioner unless they are exempt (non-profit organizations, journalistic, academic, literary expression etc.) and renew their registration annually.


Electronic Privacy Protection

Considering the protection of internet property and online data, the ePrivacy Regulations 2011 protect the communications and higher-advanced technical property and data such as social media and the telephone. In relation to international data privacy law that Ireland is involved in, the British–Irish Agreement Act 1999 Section 51 extensively states the relationship between data security between the United Kingdom and Ireland.Kuner, Christopher. 2007. ''European Data Protection Law: Corporate Compliance and Regulation.'' Oxford, United Kingdom: Oxford University Press In addition, Ireland is part of the
Council of Europe The Council of Europe (CoE; , CdE) is an international organisation with the goal of upholding human rights, democracy and the Law in Europe, rule of law in Europe. Founded in 1949, it is Europe's oldest intergovernmental organisation, represe ...
and the Organisation for Economic Cooperation and Development. The Data Protection Commissioner of Ireland is a member of the International Conference of Data Protection and Privacy Commissioners, European Data Protection Authorities, the EU Article 29 Working Party, Global Privacy Enforcement Network, and the British, Irish, and Islands Data Protection Authorities. Ireland is also the main international location for social media platforms, specifically
LinkedIn LinkedIn () is an American business and employment-oriented Social networking service, social network. It was launched on May 5, 2003 by Reid Hoffman and Eric Ly. Since December 2016, LinkedIn has been a wholly owned subsidiary of Microsoft. ...
and Twitter, for data collection and control for any data processed outside the United States.


Jamaica

The Jamaican constitution grants its people the right to "respect for and protection of private and family life, and privacy of the home". Although the government grants its citizens the right to privacy, the protection of this right is not strong. But in regards to other privacy laws that have been adopted in Jamaica, the closest one is the Private Security Regulation Authority Act. This act passed in the year 1992, establishing the Private Security Regulation Authority. This organization is tasked with the responsibility of regulating the private security business and ensuring that everyone working as a private security guard is trained and certified. The goal of this is to ensure a safer home, community, and businesses. One of the reasons as to why this law was passed is that as trained workers, the guards could ensure maximum
Customer service Customer service is the assistance and advice provided by a company to those who buy or use its products or services, either in person or remotely. Customer service is often practiced in a way that reflects the strategies and values of a firm, and ...
and also with the education they received they would be equipped how best to deal with certain situations as well as avoid actions can that could be considered violations, such as invasion of privacy. Additionally, as a member of the United Nations, the Jamaica is bound by the
Universal Declaration of Human Rights The Universal Declaration of Human Rights (UDHR) is an international document adopted by the United Nations General Assembly that enshrines the Human rights, rights and freedoms of all human beings. Drafted by a UN Drafting of the Universal D ...
which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


Japan

On 30 May 2003, Japan enacted a series of laws in the area of data protection: * The Act on the Protection of Personal Information (APPI) * The Act on the Protection of Personal Information Held by Administrative Organs (APPIHAO) * The Act on the Protection of Personal Information Held by Incorporated Administrative Agencies (APPI-IAA) Text was copied from this source, which is available under
Creative Commons Attribution 4.0 International License
The two latter acts (amended in 2016) contain provisions applicable to the protection of personal information by public sector entities.


Kenya

Kenya currently does not have a strong general privacy protection law for its constituents. But in chapter 4 — The Bill of Rights, and in the second part which is titled "Rights and Fundamental Freedoms", of the
constitution A constitution is the aggregate of fundamental principles or established precedents that constitute the legal basis of a polity, organization or other type of entity, and commonly determines how that entity is to be governed. When these pri ...
, privacy is allocated its own section. There we see that the Kenyan government express that all its people have the right to privacy, "which includes the right not to have — (a) their person, home or property searched; (b) their possessions seized; (c) information relating to their family or private affairs unnecessarily required or revealed, or (d) the privacy of their communications infringed". Although Kenya grants its people the right to privacy, there seems to be no existing document that protects these specific privacy laws. Regarding privacy laws relating to data privacy, like many African countries as expressed by Alex Boniface Makulilo, Kenya's privacy laws are far from the European 'adequacy' standard. As of today, Kenya does have laws that focus on specific sectors. The following are the sectors: communication and information. The law pertaining to this is called the Kenya Information and Communication Act. This Act makes it illegal for any licensed telecommunication operators to disclose or intercept information that is able to get access through the customer's use of the service. This law also grants privacy protection in the course of making use of the service provided by said company. And if the information of the customer is going to be provided to any third party it is mandatory that the customer is made aware of such an exchange and that some form of agreement is reached, even if the person is a family member. This act also goes as far as protecting data for Kenyans especially for the use of fraud and other ill manners. Additionally, as a member of the United Nations, Kenya is bound by
the universal declaration of Human Rights The Universal Declaration of Human Rights (UDHR) is an international document adopted by the United Nations General Assembly that enshrines the rights and freedoms of all human beings. Drafted by a UN committee chaired by Eleanor Roosevelt, ...
which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


Malaysia

After their independence from Great Britain in 1957, Malaysia's existing legal system was based primarily on English common law. The following common law
tort A tort is a civil wrong, other than breach of contract, that causes a claimant to suffer loss or harm, resulting in legal liability for the person who commits the tortious act. Tort law can be contrasted with criminal law, which deals with cri ...
s are related to personal information privacy and continue to play a role in Malaysia's legal system:
breach of confidence The tort of breach of confidence is, in United Kingdom law and the United States law, a common-law tort that protects private information conveyed in confidence. A claim for breach of confidence typically requires the information to be of a co ...
,
defamation Defamation is a communication that injures a third party's reputation and causes a legally redressable injury. The precise legal definition of defamation varies from country to country. It is not necessarily restricted to making assertions ...
,
malicious falsehood Defamation is a communication that injures a third party's reputation and causes a legally redressable injury. The precise legal definition of defamation varies from country to country. It is not necessarily restricted to making assertions ...
, and
negligence Negligence ( Lat. ''negligentia'') is a failure to exercise appropriate care expected to be exercised in similar circumstances. Within the scope of tort law, negligence pertains to harm caused by the violation of a duty of care through a neg ...
. In recent years, however, the
Court of Appeal An appellate court, commonly called a court of appeal(s), appeal court, court of second instance or second instance court, is any court of law that is empowered to Hearing (law), hear a Legal case, case upon appeal from a trial court or other ...
in Malaysia has referred less to English common law and instead looked more toward other nations with similar colonial histories and whose written constitutions are more like the
Malaysian Constitution The Federal Constitution of Malaysia (), which came into force in 1957 as the Constitution of the Federation of Malaya and was amended in 1963 to form the Constitution of Malaysia, is the supreme law of Malaysia and contains a total of 183 art ...
. Unlike the courts in these other nations, such as India's Supreme Court, the Malaysian Court of Appeal has not yet recognized a constitutionally protected right to privacy. In June 2010, the
Malaysian Parliament The Parliament of Malaysia (; Jawi script, Jawi: ) is the national legislature of Malaysia, based on the Westminster system. The bicameral parliament consists of the Dewan Rakyat (House of Representatives, Literal translation, lit. "People's As ...
passed the Personal Data Protection Act 2010, and it came into effect in 2013. It outlines seven Personal Data Protection Principles that entities operating in Malaysia must adhere to: the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle, and the Access Principle. The Act defines personal data as "'information in respect of commercial transactions that relates directly or indirectly to the data subject, who is identified or identifiable from that information or from that and other information." A notable contribution to general privacy law is the Act's distinction between personal data and sensitive personal data, which entails different protections. Personal data includes "information in respect of commercial transactions ... that relates directly or indirectly to a data subject" while sensitive personal data includes any "personal data consisting of information as to the physical or mental health or condition of a data subject, his political opinions, his religious beliefs or other beliefs of a similar nature." Although the Act does not apply to information processed outside the country, it does restrict cross-border transfers of data from Malaysia outwards. Additionally, the Act offers individuals the "right to access and correct the personal data held by data users", "the right to withdraw consent to the processing of personal data", and "the right to prevent data users from processing personal data for the purpose of direct marketing." Punishment for violating the Personal Data Protection Act can include fines or even imprisonment. Other
common law Common law (also known as judicial precedent, judge-made law, or case law) is the body of law primarily developed through judicial decisions rather than statutes. Although common law may incorporate certain statutes, it is largely based on prece ...
and business sector-specific laws that exist in Malaysia to indirectly protect confidential information include: * Official Secrets Act 1972 *
Communications and Multimedia Act 1998 The Communications and Multimedia Act 1998 () is an Act of the Parliament of Malaysia The Parliament of Malaysia (; Jawi script, Jawi: ) is the national legislature of Malaysia, based on the Westminster system. The bicameral parliament consist ...
*
Financial Services Act 2013 The Financial Services Act 2013 (), is a Malaysia Malaysia is a country in Southeast Asia. Featuring the Tanjung Piai, southernmost point of continental Eurasia, it is a federation, federal constitutional monarchy consisting of States and ...
* Islamic Financial Services Act 2013 * Labuan Financial Services and Securities Act 2010 * Labuan Islamic Financial Services and Securities Act 2010
  • Common law duty of bank confidentiality

  • Mexico

    On 5 July 2010, Mexico enacted a new privacy package, the Federal Law on Protection of Personal Data Held by Individuals, focused on treatment of personal data by private entities. The key elements included were: * Requirement of all private entities who gather personal data to publish their privacy policy in accordance to the law. * Set fines for up to $16,000,000 MXN in case of violation of the law. * Set prison penalties to serious violations.


    New Zealand

    In New Zealand, the Privacy Act 1993 (replaced by Privacy Act 2020) sets out principles in relation to the collection, use, disclosure, security and access to personal information. The introduction into the New Zealand common law of a tort covering invasion of personal privacy at least by public disclosure of private facts was at issue in ''Hosking v Runting'' and was accepted by the Court of Appeal. In ''Rogers v TVNZ Ltd'', the Supreme Court indicated it had some misgivings with how the tort was introduced, but chose not to interfere with it at that stage. Complaints about privacy are considered by th
    ''Privacy Commissioner''


    Nigeria

    Federal Republic of Nigeria's constitution offers its constituents the right to
    privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
    as well as privacy protection. The following can be found in the constitution pertaining to this: "The privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is hereby guaranteed and protected". Additionally, as a member of the United Nations, Nigeria is bound by the universal declaration of Human Rights which states in article twelve "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks". Nigeria is one of the few African countries that is building on the privacy laws. This is evident in the fact that Nine years later in the year 2008, the
    Cybersecurity Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
    and Information Protection Agency Bill was passed. This bill is responsible for the creation of the Cybersecurity and Information Protection Agency. This agency is tasked with the job of preventing
    cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
    s and regulating the Nigerian information technology industry. Additional laws have been passed that are meant to prevent the disclosure of information without permission and the intercepting of some form of transaction with or without evil intent.


    Philippines

    In Article III, Section 3, paragraph 1 of the
    1987 Constitution of the Philippines The Constitution of the Philippines ( Filipino: ''Saligang Batas ng Pilipinas'' or ''Konstitusyon ng Pilipinas'') is the supreme law of the Philippines. Its final draft was completed by the Constitutional Commission on October 12, 1986, and rat ...
    lets its audience know that "The privacy of communication and correspondence shall be inviolable except upon lawful order of the court, or when public safety or order requires otherwise as prescribed by law". Not only does this country grant the
    Filipinos Filipinos () are citizens or people identified with the country of the Philippines. Filipinos come from various Austronesian peoples, all typically speaking Filipino language, Filipino, Philippine English, English, or other Philippine language ...
    the right to privacy, but it also protects its people's right to privacy by attaching consequences to the violation of it thereof. In the year 2012, the Philippines passed the Republic Act No. 10173, also known as the "Data Privacy Act of 2012". This act extended
    privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
    regulations and laws to apply to more than just individual industries. This act also offered protection of data belonging to the people regardless of where it is stored, be it in private spheres or not. In that very same year, the cybercrime prevention law was passed. This law was "intended to protect and safeguard the integrity of computer and
    communications system A communications system is a collection of individual telecommunications networks systems, relay stations, tributary stations, and terminal equipment usually capable of interconnection and interoperation to form an integrated whole. Commu ...
    s" and prevent them from being misused. Not only does the Philippines have these laws, but it has also set aside agents that are tasked with regulating these privacy rules and due ensure the punishment of the violators. Additionally, with the constitution, previous laws that have been passed but that are in violation of the laws above have been said to be void and nullified. Another way this country has shown their dedication in executing this law is extending it to the government sphere as well. Additionally, as a member of the United Nations, the Philippines is bound by the
    Universal Declaration of Human Rights The Universal Declaration of Human Rights (UDHR) is an international document adopted by the United Nations General Assembly that enshrines the Human rights, rights and freedoms of all human beings. Drafted by a UN Drafting of the Universal D ...
    which states in article two "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks".


    Russia

    Applicable legislation: # Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, signed and ratified by the Russian Federation on 19 December 2005; # the Law of the Russian Federation "On Personal Data" as of 27 July 2006 No. 152-FZ, regulating the processing of personal data by means of automation equipment. It is the operator who is required to comply with that Act. As a general rule, consent of the individual is required for processing, i.e. obtaining, organizing, accumulating, holding, adjusting (updating, modifying), using, disclosing (including transfer), impersonating, blocking or destroying of his personal data. This rule doesn't apply where such processing is necessary for performance of the contract, to which an individual is a party.
    Data protection principles and legislation in the Russian Federation (in English)

    On-line database of the Russian laws (in Russian)

    Federal Service on supervising in the sphere of communications, information technology and mass media (in Russian)
    #In 2022, in the doctoral dissertation of Doctor of La
    A. V. Krotov
    the right of private life as an objective right was considered as a sub-branch of constitutional law, under the Subject of the sub-branch of private life law, the author proposes to understand an array of social relations that arise in the process of formation and development of peculiar, inherent exclusively given to the individual physical, mental and social characteristics that are objectively amenable to legal regulation and receive such regulation. As part of the sub-sector, the following stand out: the institution of privacy, including the sub-institution of the inviolability of the home; institution of religious identity; the institute of family relations, including the sub-institution of the right to become a parent and the sub-institution of gender identity; a communication institution that includes the sub-institution of privacy in cyberspace. Thus, taking into account modern trends in the development of society, a qualitatively different understanding of the right of private life is proposed, as a subjective right of private life, A.V. ) choosing the type and measure of acceptable behavior in the sphere of his personalization, depending on his will and consciousness and serving to satisfy his legitimate interests, coupled with the ability of an authorized subject to demand certain behavior from an obligated person and guaranteed by the state. The subjective right to privacy has the following features: it can be both individual and collective; arises in a person (individual subject) and belongs to him from the moment of birth, to the family (collective subject) from the moment of creation; not alienable; combines the norms of law, morality, in some legal systems of religion; is complex, includes negative and positive elements; its nature, as a rule, requires specification of the content in sectoral legislation; is a natural right, derived from the very rational nature of a person, mediates the characteristics of a person as a biosocial being with pronounced innate attitudes to personalize his properties, is connected and aimed at the implementation of the goals inherent in him by nature, and others. Exploring the post-Soviet model of the right to private life, A. V. Krotov notes its features associated with the special culture of Soviet society: the subordination of the individual's personal existence to public principles of morality and ethics, party duty, condemnation of individualism, and the specifics of Eastern Christian theology. In Orthodoxy, a person is not an autonomous being, a person is conceived in relation and communication with other personalities, the world and God, morality is in the center, and non-personality. A. V. Krotov comes to the conclusion that the post-Soviet model of the right to private life in the Orthodox countries of Eastern Europe, as a rule, is an adapted version of the Western doctrine, the result of the catch-up growth paradigm, a necessary and forced reaction to the evolution of technological, cultural, religious, political and legal systems of Western civilization. Approval at the end of the 20th century. of the pro-Western model of the right to private life in the former Soviet states (countries of the Eastern Christendom) occurred en masse not because of the public need for it, but for populist purposes, as a kind of emotional element that convinces people of a change in the state course, to demonstrate the pro-Western orientation of politicians who led the post-Soviet countries at the end of the twentieth century. However, the Western model of the right to private life does not coincide with the mass legal consciousness and the established system of values in Russia (as a collectivist society), with the philosophical and religious principles of Orthodoxy (the principle of conciliarity). Constitutional norms on the right to private life in Russia are developed to a lesser extent in sectoral legislation (compared to Western law).


    Singapore

    Singapore, like other Commonwealth jurisdictions, relies primarily on common law, and the law of confidence is employed for privacy protection cases. For example, privacy can be protected indirectly through various common law torts: defamation, trespass, nuisance, negligence, and breach of confidence. In February 2002, however, the Singaporean government decided that the common law approach was inadequate for their emerging globalized technological economy. Thus, the National Internet Advisory Committee published the Model Data Protection Code for the Private Sector, which set standards for personal data protection and was influenced by the EU Data Protection Directive and the OECD Guidelines on the Protection of Privacy. In the private sector, businesses can still choose to adopt the Model Code, but in 2005 Parliament decided that Singapore needed a more comprehensive legislative privacy framework. In January 2013, Singapore's Personal Data Protection Act 2012 came into effect in three separate but related phases. The phases continued through July 2014 and dealt with the creation of the Personal Data Protection Commission, the national Do Not Call Registry, and general data protection Rules. The Act's general purpose "is to govern the collection, use and disclosure of personal data by organisations" while acknowledging the individual's right to control their personal data and the organizations' legal needs to collect this data. It imposes eight obligations on those organizations that use personal data: consent, purpose limitation, notification, access, correction, accuracy, protection/security, and retention. The Act prohibits transfer of personal data to countries with privacy protection standards that are lower than those outlined in the general data protection rules. The Personal Data Protection Commission is responsible for enforcing the Act, which is based primarily on a complaints-based system. The punishments for violating the Act can include being ordered by the commission to stop collecting and using personal data, to destroy the data, or to pay a penalty of up to $1 million. Singapore has also passed various sector-specific statutes that more indirectly deal with privacy and personal information, including: * Banking Act * Statistics Act *
    Official Secrets Act An Official Secrets Act (OSA) is legislation that provides for the protection of Classified information, state secrets and official information, mainly related to national security. However, in its unrevised form (based on the UK Official Secret ...
    * Statutory Bodies and Government Companies Act *
    Central Provident Fund The Central Provident Fund Board (CPFB), commonly known as the CPF Board or simply the Central Provident Fund (CPF), is a compulsory comprehensive savings and pension plan for working Singaporeans and permanent residents primarily to fund their ...
    Act * Telecommunications Act There are also more specific acts for electronically stored information: * Spam Control Act 2007 * Electronic Transactions Act * National Computer Board Act * Computer Misuse Act


    South Africa

    The
    Constitution A constitution is the aggregate of fundamental principles or established precedents that constitute the legal basis of a polity, organization or other type of entity, and commonly determines how that entity is to be governed. When these pri ...
    of South Africa guarantees the most general right to privacy for all its citizens. This provides the main protection for
    personal data Personal data, also known as personal information or personally identifiable information (PII), is any information related to an identifiable person. The abbreviation PII is widely used in the United States, but the phrase it abbreviates has fou ...
    privacy so far. The Protection of Personal Information Act 2013 (POPI) was signed into act, focusing on data privacy and is inspired by other foreign national treaties like the European Union. Minimum requirements are presented in POPI for the act of processing personal data, like the fact that the data subject must provide consent and that the data will be beneficial, and POPI will be harsher when related to cross-border international data transfers, specifically with personal information. The recording of conversations over phone and internet is not allowed without the permission of both parties with the Regulation of Interception of Communications and Provision of Communications Related Act (2002). In addition, South Africa is part of the
    Southern African Development Community The Southern African Development Community (SADC) is an inter-governmental organization headquartered in Gaborone, Botswana. Goals The SADC's goal is to further regional socio-economic cooperation and integration as well as political and se ...
    and the
    African Union The African Union (AU) is a continental union of 55 member states located on the continent of Africa. The AU was announced in the Sirte Declaration in Sirte, Libya, on 9 September 1999, calling for the establishment of the African Union. The b ...
    .


    Sri Lanka

    In early 2022, Sri Lanka became the first country in South Asia to enact comprehensive data privacy legislation. The Personal Data Protection Act No. 9 of 2022, effective since 19 March 2022, applies to processing within Sri Lanka and extends extraterritorially to controllers or processors offering goods and services to individuals in Sri Lanka and/or monitoring their behavior in the country.


    Sweden

    The Data Act is the world's first national data protection law and was enacted in Sweden on 11 May 1973. The law was then superseded on 24 October 1998 by the Personal Data Act (Sw. ''Personuppgiftslagen'') that implemented the 1995 EU
    Data Protection Directive The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, was a European Union directive which regulated the processing of personal data within the European Union (EU) and the free movement of such data. The Data ...
    .


    Switzerland

    The main legislation over personal data privacy for the personal and private sector in Switzerland is the Swiss Federal Protection Act, specifically the Data Protection Act, a specific section under the Swiss Federal Protection Act. The Data Protection Act has been enacted since 1992 and is in charge of measuring the consent of sharing of personal data, along with other legislation like the Telecommunication Act and the Unfair Competition Act. The Act generally guides on how to collect, process, store, data, use, disclose, and destruct data. The Data Inspection Board is in charge of overseeing data breaches and privacy enforcement. Personal data must be protected against illegal use by "being processed in good faith and must be proportionate". Also, the reason for the transfer of personal data must be known by the time of data transfer. Data not associated with people (not personal data) is not protected by the Data Protection Act. In the case of data transfer to unsafe data protection countries, these are the major regulations required by the Data Protection Act: * Need of direct channels for data transfer * Individual case must have consent from receivers of data * Disclosure is accessible to public Switzerland is a white-listed country, meaning that it is a nation that has proper levels of data protection under the surveillance by the
    European Commission The European Commission (EC) is the primary Executive (government), executive arm of the European Union (EU). It operates as a cabinet government, with a number of European Commissioner, members of the Commission (directorial system, informall ...
    (EU Commission). Switzerland is not under the EU Data Protection Directive 95/46 EC. However, the data protection regulations are sufficient to meet European Union (EU) regulations without being a member of the EU. In addition, Switzerland is part of the Council of Europe and the Organisation for Economic Cooperation and Development. The Data Inspection Board of Switzerland is a member of the International Conference of Data Protection and Privacy Commissioners, European Data Protection Authorities, the EU Article 29 Working Party, and the Nordic Data Protection Authorities.


    Taiwan

    The right to privacy is not explicitly mentioned in the Republic of China Constitution, but it can be protected indirectly through
    judicial interpretation Judicial interpretation is the way in which the judiciary construes the law, particularly constitutional documents, legislation and frequently used vocabulary. This is an important issue in some common law jurisdictions such as the United St ...
    . For example, article 12 of the Constitution states "the people shall have freedom of confidentiality of correspondence" while article 10 states "the people shall have freedom of residence and of change of residence." Along with several other articles that assert the Constitution's protection of freedoms and rights of the people, the Grand Justices are able to decide how privacy protection fits into the legal system. The Justices first made reference to privacy being a protected right in the 1992 "Interpretation of Council of Grand Justices No. 293 on Disputes Concerning Debtors' Rights," but it was not directly or explicitly declared to be a right. In 1995, Taiwan passed the Computer-Processed Personal Data Protection Act which was influenced by the OECD Guidelines and enforced by each separate Ministry depending on their industry sector responsibility. It only protected personal information managed by government agencies and certain industries. In 2010, Taiwan enacted the Personal Data Protection Act that laid out more comprehensive guidelines for the public and private sectors and was still enforced by individual Ministries. In the 2010 Act, personal data is protected and defined as any "data which is sufficient to, directly or indirectly, identify that person", and includes data such as name, date of birth, fingerprints, occupation, medical records, and financial status, among many others. A few other administrative laws also deal with communication-specific personal privacy protection: * Telecommunications Act * Communications Protection and Surveillance Act Additionally, chapter 28 of the
    Criminal Code A criminal code or penal code is a document that compiles all, or a significant amount of, a particular jurisdiction's criminal law. Typically a criminal code will contain offences that are recognised in the jurisdiction, penalties that might ...
    outlines punishments for privacy violations in article 315, sections 315-1 and 315–2. The sections primarily address issues of search and seizure and criminal punishment for wrongful invasion of privacy. Finally, articles 18(I),184(I), and 195(I) of the Taiwanese
    Civil Code A civil code is a codification of private law relating to property law, property, family law, family, and law of obligations, obligations. A jurisdiction that has a civil code generally also has a code of civil procedure. In some jurisdiction ...
    address the "personality right" to privacy and the right to compensation when one injures the "rights" of another, such as when someone uses another's name illegally.


    Thailand

    Thailand's unique history of being an authoritarian buffer state during the Cold War and being under the constant threat of a
    coup d'état A coup d'état (; ; ), or simply a coup , is typically an illegal and overt attempt by a military organization or other government elites to unseat an incumbent leadership. A self-coup is said to take place when a leader, having come to powe ...
    means that privacy laws have so far been limited in order to preserve national security and public safety. Thailand uses bureaucratic surveillance to maintain national security and public safety, which explains the 1991 Civil Registration Act that was passed to protect personal data in computerized record-keeping and data-processing done by the government. The legislature passed the Official Information Act 1997 to provide basic data protection by limiting personal data collection and retention in the public sector. It defines personal information in a national context in relation to state agencies. Two communication technology related laws, the Electronic Transactions Act 2001 and the Computer Crime Act 2007, provide some data privacy protection and enforcement mechanisms. Nevertheless, Thailand still lacks legislation that explicitly addresses privacy security. Thus, with the need for a more general and all-encompassing data protection law, the legislature proposed the Personal Data Protection Bill in 2013, which is heavily influenced by the OECD Guidelines and the EU Directive. The draft law is still under evaluation and its enactment date is not yet finalized.


    Ukraine

    Privacy and
    data protection Data protection may refer to: * Information privacy, also known as data privacy * Data security {{Authority control ...
    in
    Ukraine Ukraine is a country in Eastern Europe. It is the List of European countries by area, second-largest country in Europe after Russia, which Russia–Ukraine border, borders it to the east and northeast. Ukraine also borders Belarus to the nor ...
    is mainly regulated by the Law of Ukraine No. 2297-VI 'On Personal Data Protection' enacted on 1 June 2010. On 20 December 2012 legislation was substantially amended. Some general and sector-specific aspects of privacy are regulated by the following acts: * The
    Constitution of Ukraine The Constitution of Ukraine (, ) is the fundamental law of Ukraine. The constitution was adopted and ratified at the 5th session of the ''Verkhovna Rada'', the parliament of Ukraine, on 28 June 1996. The constitution was passed with 315 ayes o ...
    ; * The
    Civil Code of Ukraine The Civil Code of Ukraine (, ''Tsyvilnyi Kodeks Ukrayiny'') is a Ukrainian codification of private law (civil code), basic normative legal act. It regulates personal non-property and property relations (civil relations), based on legal equality, ...
    ; * Law of Ukraine No. 2657-XII 'On Information' dated 2 October 1992; * Law of Ukraine No. 1280-IV 'On Telecommunications' dated 18 November 2003; * Law of Ukraine No. 80/94-BP 'On Protection of Information in the Information and Telecommunication Systems' dated 5 July 1994; * Law of Ukraine No. 675-VIII 'On Electronic Commerce' dated 3 September 2015.


    United Kingdom

    As a member of the
    European Convention on Human Rights The European Convention on Human Rights (ECHR; formally the Convention for the Protection of Human Rights and Fundamental Freedoms) is a Supranational law, supranational convention to protect human rights and political freedoms in Europe. Draf ...
    , the United Kingdom adheres to
    Article 8 of the European Convention on Human Rights Article 8 of the European Convention on Human Rights provides a right to respect for one's " private and family life, his home and his correspondence", subject to certain restrictions that are "in accordance with law" and "necessary in a democrat ...
    , which guarantees a "right to respect for privacy and family life" from state parties, subject to restrictions as prescribed by law and
    necessary in a democratic society "Necessary in a democratic society" is a test found in Articles 8–11 of the European Convention on Human Rights, which provides that the state may impose restrictions of these rights only if such restrictions are "necessary in a democratic soci ...
    towards a legitimate aim. However, there is no independent tort law doctrine which recognises a right to privacy. This has been confirmed on a number of occasions. Processing of personal information is regulated by the
    Data Protection Act 2018 The Data Protection Act 2018 (c. 12) is a United Kingdom act of Parliament (UK) which updates data protection laws in the UK. It is a national law which complements the European Union's General Data Protection Regulation (GDPR) and replaces the D ...
    , supplementing the EU
    General Data Protection Regulation The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
    , which is still in force (in amended form) after the UK's exit from the EU as "retained EU legislation". * ''
    Kaye v Robertson ''Kaye v Robertson'' 991FSR 62 is a case in English law, expressing the view that there is no right to privacy in English common law. Facts The case involved actor Gorden Kaye, who had suffered serious head injuries when a plank smashed through ...
    '' * '' Wainwright v Home Office''


    Data Protection Act of 2018

    Th
    Data Protection Act of 2018
    is the United Kingdom’s main legislation protecting personal data and how it should be collected, processed, stored and shared. In accordance to this legislature, citizens have rights such as the right to access their personal data, and the right to request their data be deleted under certain circumstances, also known as the "right to be forgotten." The Act also sets out obligations for organizations that handle personal data, including requirements for transparency in data processing, the implementation of appropriate security measures to protect data, and the need for consent from individuals before processing their data.


    Privacy and Electronic Communications Regulations

    Th
    Privacy and Electronic Communications Regulations
    established in 2003, gave citizens control in consent and disclosure of information in specific electronic communications including: * marketing calls, emails, texts and faxes * cookies and tracking technologies * secure communications * customer privacy as regards traffic and location data, billing, phone line identification, and directory listings. The goal of the Privacy and Electronic Communications Regulations is to protect individuals’ privacy and control over their electronic communications while promoting responsible and transparent practices by organizations that engage in electronic marketing and in the use of tracking technologies.


    United Kingdom General Data Protection Regulation

    The United Kingdom General Data Protection Regulation, is the domestic version of the European Union's General Data Protection Regulation (GDPR), implemented into UK law through the Data Protection Act 2018 and came into effect alongside the EU GDPR in May 2018. UK GDPR governs data protection and privacy within the UK applying to the processing of personal data by organizations operating within the UK. It includes specific provisions tailored to the UK's legal framework and requirements. Key aspects of the UK GDPR include: * Data Protection - Establishes principles for the processing of citizen's personal data under the compliance of confidentiality, integrity and availability standards. * Data Breach Notifications - Requires organizations operating within the UK to disclose any and all information regarding recent breaches to the authorities and notify all parties impacted by the breach. * Rights of Data Accessibility - Citizens have the right to access, modify, restrict and delete personal data collected by organizations. * Legal Basis for Data Processing - Organizations must comply with the legal obligations when processing personal data. * Accountability and Compliance - Organizations are required to demonstrate compliance with data protection including the implementation of security measures to protect data and to conduct Data Protection Impact Assessments while maintaining records or processing activities. The UK GDPR aims to ensure that personal data is processed legally, fairly and with full transparency while individuals are given control over the handling of their personal data. For more information about the Privacy Laws in the United Kingdom: For detailed guidance and the latest updates on compliance with United Kingdom privacy laws, businesses and individuals can refer to resources provided by the https://ico.org.uk/ and stay informed about developments in UK privacy law through expert analyses and updates.


    United States

    The right to privacy is not explicitly stated anywhere in the Bill of Rights. The idea of a right to privacy was first addressed within a legal context in the United States.
    Louis Brandeis Louis Dembitz Brandeis ( ; November 13, 1856 – October 5, 1941) was an American lawyer who served as an Associate Justice of the Supreme Court of the United States, associate justice on the Supreme Court of the United States from 1916 to ...
    (later a Supreme Court justice) and another young lawyer,
    Samuel D. Warren II Samuel Dennis Warren II (January 25, 1852 – February 18, 1910) was an American lawyer and businessman from Boston, Massachusetts. Early life and family Childhood and education Warren was born in Boston on January 25, 1852, the son of Susan Cor ...
    , published an article called "The Right to Privacy" in the ''
    Harvard Law Review The ''Harvard Law Review'' is a law review published by an independent student group at Harvard Law School. According to the ''Journal Citation Reports'', the ''Harvard Law Review''s 2015 impact factor of 4.979 placed the journal first out of ...
    '' in 1890 arguing that the
    United States Constitution The Constitution of the United States is the Supremacy Clause, supreme law of the United States, United States of America. It superseded the Articles of Confederation, the nation's first constitution, on March 4, 1789. Originally includi ...
    and
    common law Common law (also known as judicial precedent, judge-made law, or case law) is the body of law primarily developed through judicial decisions rather than statutes. Although common law may incorporate certain statutes, it is largely based on prece ...
    allowed for the deduction of a general "right to privacy". Their project was never entirely successful, and the renowned tort expert and Dean of the College of Law at University of California, Berkeley,
    William Lloyd Prosser William Lloyd Prosser (March 15, 1898 – 1972) was the Dean of the School of Law at UC Berkeley from 1948 to 1961. Prosser authored several editions of ''Prosser on Torts'', universally recognized as the leading work on the subject of tort la ...
    argued in 1960 that "privacy" was composed of four separate torts, the only unifying element of which was a (vague) "right to be left alone". The four torts were: * Appropriating the plaintiff's identity for the defendant's benefit: Appropriation of one's likeness is considered the oldest of the main American privacy torts. It involves the right to control where one's appearance and other aspects of their "likeness," such as their voice and name, appear in areas like advertising and other media. As noted by the California Jury, successful cases built on the appropriation of a person's likeness must typically involve them being harmed in some way by this usage, which was non-consensual and contributed to some benefit, often financial, to the person or company using their image. ** A rising case for the appropriation tort in the United States appeared in the early 1900s due to companies using individuals' identities and appearances without their consent on packaging and advertisements. A particularly influential case was '' Roberson v. Rochester Folding Box Co.'', in which young woman Abigail Roberson had her image placed on a flour advertisement causing embarrassment and emotional distress. Her case against the company was rejected, leading to widespread public disapproval and the creation of New York Civil Rights Law § 50 that forbid the appropriation of individuals' images in advertisements without their consent, with an emphasis on the emotional impacts of such exploitation. ** The tort was also influenced by the later case of ''Loftus v. Greenwich Lithographing Co.'', where Glady Loftus sought financial compensation for the usage of her image in a film advertisement distributed around New York City; this reflected a shift in the claims of appropriation cases from emotional damage to a lack of payment for the plaintiff's image being appropriated. ** Defenses against an accusation of appropriation include the newsworthiness of the image; consent, in which the person is argued to have opted for the usage of their likeness; and their celebrity status, as this indicates they have already publicized themselves without facing emotional damage. * Placing the plaintiff in a false light in the public eye * Publicly disclosing private facts about the plaintiff Public Disclosure of Private Facts or Publicity Given to Private Life is a tort under privacy law that protects individuals from the unauthorized dissemination of private information that is not of public concern. This tort aims to safeguard an individual's right to privacy and prevent unwarranted intrusion into their personal lives. To establish a claim for public disclosure of private facts, the following elements generally need to be proven: * Publication of Private Facts: The defendant must have publicized private information about the plaintiff. This publication can be through various means such as media outlets, social media, or any other public platform. * Information Must Be Private: The disclosed information must be of a private nature and not generally known to the public. This can include personal details about one's health, finances, relationships, or any other intimate aspects of their life. * Information Must Be Offensive to a Reasonable Person: The disclosed information must be offensive or embarrassing to a reasonable person. The court will assess whether a reasonable person would find the publication highly offensive and objectionable. * No Legitimate Public Concern: The disclosed information should not be of legitimate public concern. If the information is newsworthy or serves a public interest, it may be protected under the First Amendment, and the plaintiff may not have a valid claim. * Unreasonably intruding upon the seclusion or solitude of the plaintiff One of the central privacy policies concerning minors is the
    Children's Online Privacy Protection Act The Children's Online Privacy Protection Act of 1998 (COPPA) is a United States federal law The law of the United States comprises many levels of Codification (law), codified and uncodified forms of law, of which the supreme law is ...
    (COPPA), which requires children under the age of thirteen to gain parental consent before putting any personal information online.


    Federal Privacy Laws

    The Privacy Act of 1974 is foundational, establishing a code of fair information practices that govern the collection, maintenance, use, and dissemination of information about individuals that is maintained in systems of records by federal agencies. This act allows individuals to review and amend their records, ensuring personal information is handled transparently and responsibly by the government. Enacted in 1996, the
    Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act of 1996 (HIPAA or the Ted Kennedy, Kennedy–Nancy Kassebaum, Kassebaum Act) is a United States Act of Congress enacted by the 104th United States Congress and signed into law by President ...
    (HIPAA) protects sensitive patient health information from being disclosed without the patient's consent or knowledge. HIPAA sets the standard for protecting sensitive patient data held by health care providers, insurance companies, and their business associates. The
    Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) United States antitrust law, antitrust law and the promotion of consumer protection. It ...
    plays a crucial role in enforcing federal privacy laws that protect consumer privacy and security, particularly in commercial practices. It oversees the enforcement of laws such as the
    Fair Credit Reporting Act The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 ''et seq.'', is federal legislation enacted to promote the accuracy, fairness, and privacy of consumer information contained in the files of consumer reporting agencies. It was intended ...
    ' which regulates the collection and use of consumer credit information.


    State Privacy Laws

    Individual states also enact their own privacy laws. The
    California Consumer Privacy Act The California Consumer Privacy Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of the state of California in the United States. The bill was passed by the California State Legislature and si ...
    is one of the most stringent privacy laws in the U.S. It provides California residents with the right to know about the personal data collected about them, the right to delete personal information held by businesses, and the right to opt-out of the sale of their personal information. Businesses must disclose their data collection and sharing practices to consumers and allow consumers to access their data and opt-out if they choose. The Act recently expanded existing consumer rights in the state in 2023, providing citizens the right to reduce the collection of data and correct false information.


    Enforcement and Impact

    Enforcement of these laws is specific to the statutes and the authorities responsible. For instance, HIPAA violations can lead to substantial fines imposed by the Department of Health and Human Services, while the Federal Trade Commission handles penalties under consumer protection laws. State laws are enforced by respective state attorneys general or designated state agencies. The privacy laws in the U.S. reflect a complex landscape shaped by sector-specific requirements and state-level variations, illustrating the challenge of protecting privacy in a federated system of government. For additional information on Privacy laws in the United States, see: *
    Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act of 1996 (HIPAA or the Ted Kennedy, Kennedy–Nancy Kassebaum, Kassebaum Act) is a United States Act of Congress enacted by the 104th United States Congress and signed into law by President ...
    (HIPAA) * Right to Financial Privacy Act of 1978 * Financial Services Modernization Act (GLB)
    15 U.S. Code §§ 6801–6810

    Final Rule on Privacy of Consumer Financial Information, 16 Code of Federal Regulations, Part 313
    *
    Fair Credit Reporting Act The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 ''et seq.'', is federal legislation enacted to promote the accuracy, fairness, and privacy of consumer information contained in the files of consumer reporting agencies. It was intended ...
    (FCRA)
    15 U.S. Code §§ 1681-1681u
    *
    Fair Debt Collection Practices Act The Fair Debt Collection Practices Act (FDCPA), Pub. L. 95-109; 91 Stat. 874, codified as –1692p, approved on September 20, 1977 (and as subsequently amended), is a consumer protection amendment, establishing legal protection from abusive d ...
    (FDCPA)
    15 U.S.C. §§ 1692-1692
    *
    Driver's Privacy Protection Act The Driver's Privacy Protection Act of 1994 (also referred to as the "DPPA"), Title XXX of the Violent Crime Control and Law Enforcement Act, is a United States federal law, United States federal statute governing the privacy and disclosure of pe ...
    (DPPA)
    18 U.S.C. §§ 2721–2725

    Clinger-Cohen Act of 1996

    Computer Fraud and Abuse Act of 1986

    E-Government Act of 2002
    Recently, a handful of lists and databases are emerging to help risk managers research U.S. State and Federal laws that define liability. They include: * Perkins Coie Security Breach Notification Chart: A set of articles (one per state) that define data breach notification requirements among U.S. states. *NCSL Security Breach Notification Laws: A list of U.S. state statutes that define data breach notification requirements. *ts jurisdiction: A commercial cybersecurity research platform with coverage of 380+ U.S. State & Federal laws that impact cybersecurity before and after a breach. ts jurisdiction also maps to the NIST Cybersecurity Framework.


    Unreasonably Intruding Upon the Seclusion or Solitude of the Plaintiff

    To be able to intrude on someone's seclusion, the person must have a "legitimate expectation of privacy" in the physical place or personal affairs intruded upon. To be successful, a plaintiff "must show the defendant penetrated some zone of physical or sensory privacy" or "obtained unwanted access to data" in which the plaintiff had "an objectively reasonable expectation of seclusion or solitude in the place, conversation or data source." For example, a delicatessen employee told co-workers that she had a staph infection in a private manner. The co-workers then informed their manager, who directly contacted the employee's doctor to determine if she actually had a staph infection, because employees in Arkansas with a communicable disease are forbidden from working in the food preparation industry due to transmittable health concerns. The employee with the staph infection sued her employer, the deli, for intruding on her private affairs, as the information she had previously shared had gotten leaked. The court held that the deli manager had not intruded upon the worker's private affairs because the worker had made her staph infection public by telling her two co-workers about it, no longer making it intrusion. The court said: "When Fletcher learned that she had a staph infection, she informed two coworkers of her condition. Fletcher's revelation of private information to coworkers eliminated Fletcher's expectation of privacy by making what was formerly private a topic of office conversation."


    Offensiveness

    In determining whether an intrusion is objectively "highly offensive," a court is supposed to examine "all the circumstances of an intrusion, including the motives or justification of the intruder." It is up to the courts to decide whether someone that is considered "offensive" is acceptable based on the intentions when it comes to searching for that specific news.


    Websites' Data Collection

    A website may commit a "highly offensive" act by collecting information from website visitors using "duplicitous tactics." A website that violates its own privacy policy does not automatically commit a highly offensive act according to the jury. But the Third Circuit Court of Appeals has held that Viacom's data collection on the Nickelodeon website was highly offensive because the privacy policy may have deceptively caused parents to allow their young children to use Nick.com, thinking it was not collecting their personal information.


    The Press

    The First Amendment "does not immunize the press from torts or crimes committed in an effort to gather news." They are still held liable for the news they gather and how they gather it. But the press is given more latitude to intrude on seclusion to gather important information, so many actions that would be considered "highly offensive" if performed by a private citizen may not be considered offensive if performed by a journalist in the "pursuit of a socially or politically important story." (under the paragraph discussing COPPA) In California, the California Consumer Privacy Act of 2018 provides specific regulations for companies collecting consumer data in California organized as particular rights; these include the right to have knowledge about how companies intend to use consumer data, as well as the right to opt-out of its collection and potentially delete this data. The Act recently expanded existing consumer rights in the state in 2023, providing citizens the right to reduce the collection of data and correct false information.


    Uzbekistan

    Though the right to privacy exists in several regulations, the most effective privacy protections come in the form of constitutional articles of Uzbekistan. Varying aspects of the right to privacy are protected in different ways by different situations.


    Vietnam

    Vietnam, lacking a general data protection law, relies on Civil Code regulations relating to personal data protection. Specifically, the Code "protects information relating to the private life of a person." The 2006 Law on Information Technology protects personal information, such as name, profession, phone number, and email address, and declares that organizations may only use this information for a "proper purpose". The legislation, however, does not define what qualifies as proper. The 2005 Law on Electronic Transactions protects personal information during electronic transactions by prohibiting organizations and individuals from disclosing "part or all of information related to private and personal affairs ... without prior agreement." The 2010 Law on Protection of Consumers' Rights provides further protection for consumer information, but it does not define the scope of that information or create a data protection authority; additionally, it is only applicable in the private sector. In 2015, the Vietnam legislature introduced the Law on Information Security, which ensures better information safety and protection online and in user's computer software. It took effect on 1 July 2016 and is Vietnam's first overarching data protection legislation.


    Countries without official data privacy laws

    ''Source'' * Afghanistan * Algeria * Bahrain * Bangladesh * Belize * Bolivia * Botswana * Burundi * Cambodia * Cameroon * Central African Republic * Comoros * Cuba * Djibouti * Ecuador * Egypt * El Salvador * Equatorial Guinea * Eritrea * Ethiopia * Fiji * Gambia * Guatemala * Guinea * Haiti * Iran * Iraq * Jordan * Kiribati * Kuwait * Lebanon * Liberia * Libya * Malawi * Maldives * Mongolia * Mozambique * Myanmar * Namibia * Nauru * Oman * Pakistan * Palau * Palestine * Panama * Papua New Guinea * Rwanda * Samoa * Saudi Arabia * Sierra Leone * Somalia * Sudan * Syria * Tajikistan * Timor-Leste * Togo * Tonga * Turkmenistan * Tuvalu * United Arab Emirates * Uzbekistan * Vanuatu * Vatican (Holy See) * Venezuela * Zambia


    See also

    *
    Data Protection Act 1998 The Data Protection Act 1998 (c. 29) (DPA) was an act of Parliament of the United Kingdom designed to protect personal data stored on computers or in an organised paper filing system. It enacted provisions from the European Union (EU) Data Pr ...
    (United Kingdom) *
    Data Protection Directive The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, was a European Union directive which regulated the processing of personal data within the European Union (EU) and the free movement of such data. The Data ...
    (European Union) * Data protection and privacy laws (Russia) *
    Electronic Communications Privacy Act The Electronic Communications Privacy Act of 1986 (ECPA) was enacted by the United States Congress to extend restrictions on government wire taps of telephone calls to include transmissions of electronic data by computer ( ''et seq.''), added n ...
    (United States) *
    General Data Protection Regulation The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
    (European Union) *
    Information Privacy Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, contextual information norms, and the legal and political issues surrounding them. It is also known as dat ...
    *
    Information Privacy Law Information privacy, data privacy or data protection laws provide a legal framework on how to obtain, use and store data of natural persons. The various laws around the world describe the rights of natural persons to control who is using their da ...
    *
    Personality rights Personality rights, sometimes referred to as the right of publicity, are rights for an individual to control the commercial use of their identity, such as name, image, likeness, or other unequivocal identifiers. They are generally considered as p ...
    *
    Privacy Act of 1974 Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of ...
    (United States) *
    Privacy Act 1988 The ''Privacy Act 1988'' is an Australian law dealing with privacy. Section 14 of the Act stipulates a number of privacy rights known as the Australian Privacy Principles (APPs). These principles apply to Australian Government and Australian C ...
    (Australian) *
    Regulation of algorithms Regulation of algorithms, or algorithmic regulation, is the creation of laws, rules and public sector policies for promotion and regulation of algorithms, particularly in artificial intelligence and machine learning. For the subset of AI algorith ...
    *
    Right to be forgotten The right to be forgotten (RTBF) is the right to have private information about a person be removed from Internet searches and other directories in some circumstances. The issue has arisen from desires of individuals to "determine the developmen ...


    References

    # Belkhamza, Zakariya. 2017. "The Effect of Privacy Concerns on Smartphone App Purchase in Malaysia: Extending the Theory of Planned Behavior." International Journal of Interactive Mobile Technologies 11(5):178-194. # Bhasin, Madan Lal. 2016. "Challenge of guarding online privacy: role of privacy seals, government regulations and technological solutions." Socio-Economic Problems & the State 15(2):85-104. # Bignami, Francesa. 2011. "Cooperative Legalism and the Non-Americanization of European Regulatory Styles: The Case of Data Privacy." The American Journal of Comparative Law 59(2):411-461. # Butt, Lesli. 2011. "Can you keep a secret? Pretences of confidentiality in HIV/AIDS counseling and treatment in eastern Indonesia." Medical Anthropology 30(3):319-338. # Chandran, Ravi. 2000. "Privacy in Employment." Singapore Journal of Legal Studies 2000(1):263-297. # Chesterman, Simon. 2012. "After Privacy: The Rise of Facebook, the Fall of WikiLeaks, and Singapore’s ‘Personal Data Protection Act 2012.’" Singapore Journal of Legal Studies 391-415. # Chik, Warren B. 2013. "The Singapore Personal Data Protection Act and an assessment of future trends in data privacy reform." Computer Law & Security Review: The International Journal of Technology Law and Practice 29(5):554-575. # Dove, Edward S. 2015. "Biobanks, Data Sharing, and the Drive for a Global Privacy Governance Framework." Journal of Law, Medicine & Ethics 43(4):675-689. # Greenleaf, Graham. 2009. "Five years of the APEC Privacy Framework: Failure or promise?" Computer Law and Security Review: The International Journal of Technology and Practice 25(1):28-43. # Greenleaf, Graham. 2012. "Independence of data privacy authorities (Part 1): International standards." Computer Law & Security Review 28(1):3-13. # Hew, Khe Foon, and Wing Sum Cheung. 2012. "Use of Facebook: A Case Study of Singapore Students’ Experience." Asia Pacific Journal of Education 32(2):181-196. # Llanillo, Llewellyn L., and Khersien Y. Bautista. 2017. "Zones of Privacy: How Private?" Defense Counsel Journal 1-27. # Marvin, Lynn M. and Yohance Bowden. 2015. "Conducting U.S. Discovery in Asia: An Overview of E- Discovery and Asian Data Privacy Laws." Richmond Journal of Law & Technology 21(4):1-55. # Mehta, Michael D. 2002. "Censoring Cyberspace." Asian Journal of Social Sciences 30(2):319-338. # Mitsilegas, Valsamis. 2016. "Surveillance and Digital Privacy in the Transatlantic "War on Terror": The Case for a Global Privacy Regime." Columbia Human Rights Law Review 47(3):1-77. # Peng, Shin-Yi. 2003. "Privacy and the Construction of Legal Meaning in Taiwan." The International Lawyer 37(4):1037-1054. # Tene, Omer. 2013. "Privacy Law’s Midlife Crisis: A Critical Assessment of the Second Wave of Global Privacy Laws." Ohio State Law Journal 74(6):1217-1261. # Thomas, Mathews. 2004. "Is Malaysia’s MyKad the ‘one card to rule them all’? The urgent need to develop a proper legal framework for the protection of personal information in Malaysia." Melbourne University Law Review 1-38. # Ramasoota, Pirongrong and Sopak Panichpapiboon. 2014. "Online Privacy in Thailand: Public and Strategic Awareness." Journal of Law, Information & Science 23(1):97-136. # Reidenberg, Joel R. 2000. "Resolving Conflicting International Data Privacy Rules in Cyberspace." Stanford Law Review 52(5):1315-1371. # Federal Trade Commission. "Protecting Consumer Privacy and Security". Retrieved 24 April 2024. # California Office of the Attorney General. "California Consumer Privacy Act". Retrieved 24 April 2024. # U.S. Department of Justice. "Overview of the Privacy Act of 1974 - 2020 Edition". Retrieved 24 April 2024. # Library of Parliament (Canada). "Privacy Law in Canada". Retrieved 24 April 2024. # DataGuidance. "Canada - Data Protection Overview". Retrieved 24 April 2024. # Office of the Privacy Commissioner of Canada. "Privacy Laws in Canada". Retrieved 24 April 2024. # HealthIT.gov. "Health Information Privacy Law and Policy". Retrieved 24 April 2024. # Columbia Global Freedom of Expression. "Jones v. Tsige". Retrieved 24 April 2024. # Government of Canada. "Canada Anti-Spam Legislation". Retrieved 24 April 2024. # Warren and Brandeis (15 December 1890). "The Right to Privacy". ''Harvard Law Review''. IV (5): 193–220. doi:10.2307/1321160.
    JSTOR JSTOR ( ; short for ''Journal Storage'') is a digital library of academic journals, books, and primary sources founded in 1994. Originally containing digitized back issues of academic journals, it now encompasses books and other primary source ...
    1321160. # "General Data Protection Regulation (GDPR) – Legal Text". ''General Data Protection Regulation (GDPR)''. Retrieved 2024-04-27.


    External links


    2014 International Compendium of Data Privacy Laws
    provided by
    BakerHostetler BakerHostetler is an American law firm founded in 1916. One of the firm's founders, Newton D. Baker, was U.S. Secretary of War during World War I, and former Mayor of Cleveland, Ohio. History , the firm was ranked the 73rd-largest law firm in t ...

    Handbook on European data protection law
    {{DEFAULTSORT:Privacy Law Data laws
    Law Law is a set of rules that are created and are enforceable by social or governmental institutions to regulate behavior, with its precise definition a matter of longstanding debate. It has been variously described as a science and as the ar ...