News
The internet has changed dramatically over the past decade. What was once something of a digital Wild West has, year by year, come under increasing regulatory scrutiny aimed at better protecting personal data and, by extension, the privacy of web users. Beginning with the EU, a wave of global privacy regulations has continued to expand, reaching nearly every major jurisdiction. According to the IAPP, 144 countries have now enacted national global data privacy laws, bringing approximately 6.64 billion people (about 82% of the world’s population) under the protection of some form of data-privacy legislation.
Over the past several years, we have provided semi-regular updates on privacy laws around the world as they have fallen into place. In this article, we will aim to provide a more extensive overview of global data protection and privacy laws, as well as updates on changes to long-standing legislation such as the GDPR. As with our previous blogs, this blog is for general information purposes only and is not intended to represent regulatory, legal, or other professional advice.
The EU’s laws have become de facto templates for the majority of international privacy laws and are the reason for the ubiquitous consent pop-ups delivered through Consent Management Platforms (CMPs).
The core data protection regime in the EU has been in force since May 2018. The law governs personal data processing, lawful bases, and automated decision-making, among other things. GDPR requires publishers and advertisers to obtain clear, lawful consent for data-driven advertising and to limit, document, and justify how they collect, share, and process user data. One clear impact has been to fundamentally reshape targeting, measurement, and monetisation practices across the digital advertising ecosystem. However, the EU is, as of December 2025, considering rewriting parts of the law to cut red tape by in part narrowing the definition of personal data. This has raised fears among privacy advocates that consumer protections will in effect be watered down.
Adopted in 2002 and amended in 2009, the ePrivacy Directive governs online tracking and electronic communications across the EU. Its national implementations, such as those in France, Spain, Italy, Ireland, and Germany, set country-specific requirements for cookies, third-party tags, tracking pixels, and for regulating email marketing and other unsolicited communications. The ePrivacy Directive is also being reviewed by the EU as part of its drive to cut red tape, which is likewise leading to concerns among privacy advocates (see GDPR above). A proposed ePrivacy Regulation, intended to modernise and replace the ePrivacy Directive, has been stalled for years due to political disagreement among EU member states over how strict the rules should be and how they would impact digital business models, security, and innovation.
The DSA increases transparency and accountability across the digital advertising supply chain by requiring clear disclosure of ad targeting criteria, restricting certain forms of targeting (especially for minors and sensitive data), and imposing stricter obligations on large platforms that directly affect how publishers and advertisers deliver, optimise, and measure ads.
The DMA restricts how “gatekeeper” platforms can combine and use personal data across their services, forcing greater transparency, limiting cross-service targeting without consent, and reshaping how publishers and advertisers can access, measure, and monetise audiences within dominant digital ecosystems.
The EU GDPR and UK GDPR remain broadly aligned, sharing the same core principles, obligations, and rights. The key differences stem from Brexit: the UK now has its own regulator, its own adequacy decisions, and the potential to diverge through future reforms.
The UK Data Protection Act 2018 sits alongside the UK GDPR and provides the national legal framework for how personal data must be collected, used, and protected in the UK. It tailors GDPR rules to the UK context, sets out enforcement powers for the ICO, and includes additional provisions on law enforcement and intelligence services.
The Privacy and Electronic Communications Regulations (PECR) set the UK’s rules for cookies, tracking technologies, and electronic marketing, operating alongside the UK GDPR. They require consent for most non-essential cookies and tightly regulate email, SMS, and phone marketing practices. For publishers and advertisers, PECR is the law that directly governs how they track users and communicate with audiences.
In the US, publishers and advertisers must meet the obligations set out in both federal and state law. The following are key federal laws:
Federal Trade Commission Act, Section 5
Section 5 of the FTC Act prohibits “unfair or deceptive acts or practices,” and the FTC has long relied on this broad authority to enforce privacy and data-protection standards in the absence of a comprehensive federal privacy law. For publishers and advertisers, Section 5 is effectively the primary US federal rule governing truthful data practices, transparency, and user choice.
Children’s Online Privacy Protection Act (COPPA)
COPPA is the primary US federal law protecting the online privacy of children under 13, requiring websites, apps, and online services directed to children, or knowingly collecting data from them, to obtain verifiable parental consent before collecting, using, or sharing personal information.
The CAN-SPAM Act sets the national rules for commercial email in the US, requiring clear identification of marketing messages, truthful subject lines, and an easy, functioning opt-out mechanism. It prohibits deceptive header information and mandates that senders honour unsubscribe requests promptly.
Health Insurance Portability and Accountability Act (HIPAA) / Gramm-Leach-Bliley Act (GLBA)
For publishers and agencies that are involved with companies in healthcare and financial services, HIPAA and GLBA impose strict limits on how data can be collected, used, or shared. The laws reflect the potential impact on consumers on the loss or theft of highly sensitive health or financial data
As of late 2025, 20 US states have enacted consumer privacy laws, most now in force. While these share a common foundation with broader trends in international data protection and privacy law, there are some differences.
Broadly, these rules give consumers rights to access, delete, correct, and opt out of targeted advertising, data sales, and profiling, while requiring businesses to provide clear notices and uphold reasonable data-protection practices. However, states diverge on key operational details: for example, while California maintains strict recognition of universal opt-out signals, and heightened protections for sensitive data; Florida takes a narrower, platform-focused approach; and Texas applies broadly but follows a more business-friendly model. Key rules include:
Privacy frameworks across Latin America closely mirror the GDPR and form an important regional component of data privacy regulations around the world, though each country applies the model with its own nuances. Brazil’s LGPD, for example, is comprehensive and influential, featuring broad extraterritorial reach, detailed legal bases, strong data-subject rights, as well as active enforcement. Meanwhile, Argentina’s EU-adequate Law 25.326 and Colombia’s Law 1581 offer robust protection but with less granularity. Key rules in the region include:
In the Middle East and Africa, most modern privacy frameworks follow the GDPR template, reflecting the region’s increasing alignment with broader data protection regulations around the world, yet each jurisdiction applies the model with its own emphasis.
Laws such as the UAE PDPL, Saudi Arabia’s PDPL, and Qatar’s PDP Law, all adopt GDPR-style concepts such as lawful bases, data-subject rights, controller/processor distinctions, breach notification, and cross-border transfer rules. However, jurisdictions across the region can differ in enforcement maturity, data-localisation requirements, government-access provisions, and registration or licensing obligations. Notably, some Middle Eastern laws (for example, early versions of Saudi Arabia’s PDPL) have been more restrictive around data residency, and several African regimes retain regulator registration requirements absent from the GDPR. Key laws include:
Many data protection regimes in Asia Pacific also draw on the principles established in the GDPR. For example, laws such as APPI in Japan, PIPA in South Korea, Thailand’s PDPA, and many others in Southeast Asia now grant data-subject rights, require lawful bases for data processing (including consent or legitimate interest), mandate breach-notification regimes, and impose restrictions on cross-border transfers.
However, there are some differences, reflecting diverse legal traditions, regulatory priorities, and commercial contexts. Some APAC laws are more flexible or less prescriptive: for instance, laws like the PDPA of the Philippines or the Malaysia PDPA tend to have narrower scopes or include significant exemptions. China’s PIPL, meanwhile, is a more security-driven, sovereignty-focused law. Key laws include:
It’s clear that global privacy laws and global data protection laws are reshaping digital advertising. What began with the GDPR has expanded into a truly worldwide movement, with nearly every major market imposing stricter rules on tracking, consent, profiling, and cross-border data use.
For publishers and advertisers, the message is consistent across jurisdictions: legacy programmatic signals – especially those reliant on opaque third-party tracking or insufficient consent – are risky and, in many cases, no longer viable. The cost of non-compliance now includes not just regulatory penalties, but also the erosion of user trust and potential customer churn.
The path forward lies in building advertising ecosystems where user privacy is baked in from the outset. Privacy-preserving, consent-based solutions such as telco-verified IDs offer exactly that: effective identity signals that are rooted in deterministic data. These approaches reduce reliance on outdated tracking cookies or device IDs and create a more transparent value exchange between brands, publishers, and audiences.