Privacy regulation refers to the body of laws and rules that govern how organisations collect, process, store, and share personal data, granting individuals rights over information about them. Such regulation establishes lawful bases for processing, mandates transparency and security obligations, and provides for enforcement and penalties for non-compliance. Prominent examples set global benchmarks for data subject rights, consent, and accountability, shaping how digital products handle personal information across jurisdictions.

Overview

  • Privacy regulation codifies how personal data may lawfully be used.
  • It defines individual rights such as access, erasure, and portability.
  • It imposes accountability, transparency, and security duties on controllers.
  • Enforcement bodies levy penalties for breaches of the rules.

Key aspects

  • Lawful bases such as consent or legitimate interest.
  • Data subject rights including access and erasure.
  • Breach-notification and security obligations.
  • Cross-border transfer safeguards.
  • Privacy by design embedded into systems.

Applications

  • Compliance programmes for digital platforms.
  • Consent management and cookie governance.
  • Data-handling controls in analytics and marketing.
  • Cross-jurisdictional data transfer arrangements.

Provenance