Global Privacy Regulations
Navigate the complex landscape of privacy and cookie consent laws across different regions
| Control | Implemented scope | Customer responsibility |
|---|---|---|
| Location-scoped consent model | EU/UK, Brazil, Canada, China, Australia, India, Japan, South Korea, South Africa, Thailand, and California | Confirm applicability and select automatic, selected-law, or force-global opt-in behavior. |
| Opt-out and GPC | California opt-out control; GPC conservatively denies analytics, marketing, and sensitive categories wherever detected | Do not load untagged sale/share or advertising vendors before CookieGuard. |
| Sensitive / health data | Explicit, never-prechecked category for eligible Washington MHMDA and Nevada health-data configurations on the Healthcare plan | Determine whether data and purposes are covered and obtain any separate sharing or sale authorization required. |
| Enforcement and evidence | Google Consent Mode v2, deliberately tagged scripts, revocation callbacks, server-normalized audit records, export, and configured retention | Tag or integrate every optional vendor and validate the complete site in the jurisdictions served. |
| Not included | IAB TCF, Google CMP certification, legal opinions, DSR workflows, and automatic discovery/blocking of untagged scripts | Use separate services and legal review where those capabilities are required. |
| Regulation | Region | Consent Required | Right to Access | Right to Delete | Penalties |
|---|---|---|---|---|---|
| GDPR 2018 | European Union | Up to €20M or 4% of global revenue | |||
| CCPA/CPRA 2020/2023 | California, USA | $2,500-$7,500 per violation | |||
| LGPD 2020 | Brazil | Up to 2% of revenue in Brazil (max R$50M) | |||
| PIPEDA 2000 | Canada | Varies by province | |||
| POPIA 2020 | South Africa | Up to R10M or imprisonment | |||
| PDPA 2012/2019 | Singapore/Thailand | Up to S$1M (SG) or ฿5M (TH) |
Key Requirements
- Explicit consent required before setting non-essential cookies
- Detailed information about data collection and processing
- Easy-to-use consent withdrawal mechanism
- Data subject rights (access, deletion, portability)
- 72-hour breach notification
Cookie Banner Requirements
- No pre-ticked boxes for consent
- Granular consent options for different cookie categories
- Equal prominence for "Accept" and "Reject" options
- No cookie wall (blocking access without consent)
Key Requirements
- Similar to EU GDPR with UK-specific adaptations
- ICO (Information Commissioner's Office) enforcement
- Explicit consent for cookies (from ePrivacy Directive)
- Potential divergence from EU GDPR over time
Recent Developments
The UK is exploring its own data protection framework post-Brexit, potentially creating a more business-friendly approach while maintaining high standards of data protection.
The ePrivacy Regulation is set to replace the current ePrivacy Directive and will work alongside the GDPR to provide specific rules for electronic communications. It aims to streamline cookie consent requirements and potentially introduce browser-level consent mechanisms.
Build consistent consent controls across regions
CookieGuard uses maintained location-scoped rules, explicit fallback behavior, and auditable decisions to support your privacy program. It does not replace correct tag installation, vendor classification, disclosures, or legal review.