Personal data protection in different countries: GDPR, CCPA and other regimes

Barbashyn Law Team Barbashyn Law Team
24 July, 2026 10 min read
24 July, 2026 10 min read

Personal data protection is a set of legal, technical, and organizational measures that determine how companies may collect, store, process, and transfer information about individuals. Depending on the jurisdiction, these rules vary significantly, ranging from the strict regulation of the EU to the sectoral approach in the US and stringent government oversight in China. For Ukrainian businesses entering international markets, compliance is becoming not just a legal obligation but also a competitive advantage.

Why personal data regulation has become a global issue

The phenomenon known as the “Brussels Effect” describes the EU’s ability to establish global standards through its own legislation. One of the most prominent examples is the EU’s General Data Protection Regulation (GDPR), which entered into force in May 2018. Due to its extraterritorial scope, the GDPR has effectively compelled companies around the world to reconsider their approaches to data processing.

According to the International Association of Privacy Professionals (IAPP), as of 2025, at least 144 countries have their own personal data protection legislation¹, with most of them drawing, to some extent, on the European model. Even the US, which has traditionally avoided comprehensive federal regulation, is gradually moving toward stricter requirements at the state level.

When your company needs to start thinking about compliance

Most personal data protection regimes apply the principle of extraterritoriality: the law applies not only to companies registered in the relevant jurisdiction but also to any business that processes the data of residents of that country. This means that even a Ukrainian company with no office in the EU is required to comply with the GDPR if it offers goods or services to customers in the EU.

Signs that your company may be subject to the GDPR:

  • the website is available in one of the languages spoken in the countries of the European Economic Area (EEA);
  • prices for goods or services are listed in the currencies of EU member states (euro, zloty, krone, etc.);
  • the company uses telephone numbers from EEA countries or top-level domains (.de, .pl, .nl, .eu);
  • the company refers to an international customer base or specifically targets consumers in the EEA;
  • the company delivers goods or provides services in EU countries.

A similar principle of extraterritoriality applies to the CCPA (California), LGPD (Brazil), and most other modern data protection laws.

The European model: GDPR as a global standard

The GDPR (General Data Protection Regulation) is the EU’s primary legal framework for personal data protection, establishing common standards across all 27 EU member states and the European Economic Area. Importantly, the GDPR applies not only to companies within the EU but also to any controller or processor outside the EU that processes the data of individuals located in the EU, through the principle of extraterritoriality and the mechanisms for appointing an EU representative. Violations may result in fines of up to €20 million or 4% of a company’s total worldwide annual turnover, whichever is higher.

The processing of personal data under the GDPR must be based on seven principles:

  • Lawfulness, fairness, and transparency: processing must be based on one of six lawful bases (consent, contract, legal obligation, protection of vital interests, performance of a task carried out in the public interest, or the legitimate interests of the controller). Data subjects must be informed about the purpose of processing.
  • Purpose limitation: data must be collected for specific, explicit, and legitimate purposes and must not be processed in a manner incompatible with those purposes.
  • Data minimization: only data that is necessary and adequate to achieve the intended purpose should be processed.
  • Accuracy: personal data must be accurate and kept up to date; inaccurate data must be corrected or deleted.
  • Storage limitation: data must be retained only for as long as necessary to fulfill the purpose of processing.
  • Integrity and confidentiality: processing must be carried out using appropriate technical and organizational measures to protect data against unauthorized access, loss, or damage.
  • Accountability: controllers must not only comply with these principles but also be able to demonstrate such compliance.

For an initial assessment of a website’s compliance with GDPR requirements, you can use the 2GDPR tool (2gdpr.com), which scans websites for cookies, tracking technologies, and SSL protection.

Regulation in Ukraine

In Ukraine, the processing and protection of personal data are regulated by the Law of Ukraine “On Personal Data Protection” (2010). The law establishes the main principles of data processing, the rights of data subjects, and the obligations of personal data controllers and processors. The authorized body in this area is the Ukrainian Parliament Commissioner for Human Rights (Ombudsman).

Since 2019, Ukraine has been actively aligning its legislation with EU standards under the Association Agreement. In particular, a new draft law based on the GDPR is being developed, which provides for stronger data subject rights, the introduction of the DPO framework, and increased liability for violations. However, the specific timeline for its adoption remains uncertain, so compliance planning should currently be based on the existing law.

What this means in practice:

  • For companies operating exclusively in the Ukrainian domestic market, the current law is the primary regulatory framework.
  • For companies processing the data of residents of the EU or other jurisdictions, the relevant foreign legislation also applies in parallel — first and foremost, the GDPR.
  • Liability for violations of the current Ukrainian law is administrative and significantly lower than the sanctions under the GDPR. This does not mean that compliance is less important: enforcement is becoming stricter, and new rules may come into force in the coming years.
  • Companies that engage customers or partners from the EU are, in practice, already required to comply with GDPR standards, even if their primary market is Ukraine.

The American approach: sector-specific regulation

Unlike the EU, the United States does not have a single comprehensive federal law governing personal data protection. Regulation is sector-specific and implemented through separate laws for particular industries, as well as through state-level legislation, which is rapidly evolving.

Federal sector-specific laws

HIPAA (Health Insurance Portability and Accountability Act) — establishes privacy and security standards for health information. It covers healthcare providers, health insurance companies, and their business associates.

COPPA (Children’s Online Privacy Protection Act) — regulates the processing of personal data of children under the age of 13 online. It requires website operators to obtain verifiable parental consent.

GLBA (Gramm-Leach-Bliley Act) — regulates the use of personal data in the financial sector, requiring financial institutions to protect the privacy and security of their customers’ information.

State legislation

CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act) — one of the most influential state-level privacy frameworks, incorporating many elements of the GDPR. It grants California residents the right to know what data is collected about them, request its deletion, opt out of the sale or sharing of their data, and access the information collected about them.

VCDPA (Virginia Consumer Data Protection Act) — grants Virginia residents the rights to access, correct, and delete their personal data, as well as to limit its processing for targeted advertising purposes.

CPA (Colorado Privacy Act) — among the first US state privacy laws to introduce specific requirements concerning the use of artificial intelligence and automated decision-making, including measures aimed at addressing discrimination risks associated with personal data.

It is important to note that privacy regulation in the US is primarily developed at the state level, and the rights of consumers and obligations of businesses may vary significantly from one state to another. For companies planning to operate in the US market, it is critical to determine in advance which states they will operate in.

Regulation in other countries

There is no single model of privacy regulation worldwide. For international businesses, this means that requirements can vary significantly depending on the market.

United Kingdom (UK GDPR)

Following Brexit, the United Kingdom retained standards closely aligned with the GDPR but is gradually developing its own regulatory framework. Oversight is carried out by the Information Commissioner’s Office (ICO). Companies processing personal data in the UK should pay attention to the requirement to register with the ICO and pay an annual fee.

Australia (Privacy Act 1988)

The primary legislation is the Privacy Act 1988, together with the Australian Privacy Principles (APPs). Businesses should consider requirements concerning transparency in data processing, restrictions on using personal information for purposes other than those for which it was collected, and ensuring an adequate level of protection when transferring data across borders.

Brazil (LGPD)

The LGPD (Lei Geral de Proteção de Dados) is often referred to as the “South American GDPR.” Brazil is a regional leader in personal data protection, with the LGPD drawing heavily on the European approach, including requirements for transparency, the appointment of a DPO, and respect for data subject rights. Penalties for violations can reach up to 2% of a company’s annual revenue from its activities in Brazil, capped at 50 million Brazilian reais per violation. Depending on the nature of the violation, administrative sanctions and suspension of activities may also apply.

China (PIPL)

The PIPL (Personal Information Protection Law), which entered into force in November 2021, is one of the strictest personal data protection regimes in terms of government oversight. Key features include stringent data localization requirements (storing data within China), separate consent requirements for processing sensitive personal information, and mandatory government security assessment procedures for certain cross-border data transfers. Penalties for violations can reach up to 50 million yuan or 5% of a company’s annual turnover, whichever is higher, along with administrative and criminal liability for responsible individuals. Companies operating with users in China are required to comply with the PIPL.

Japan (APPI)

The APPI (Act on the Protection of Personal Information) combines user protection with flexibility for businesses. Companies are required to clearly define the purpose of using personal data and limit its use to that purpose. As of 2025, key requirements include mandatory notification to data subjects and the regulator (PPC) of data breaches that meet established criteria, as well as restrictions on cross-border data transfers — either the data subject’s consent is required, or the recipient country must be confirmed to provide an adequate level of protection. Violations may result in fines and criminal liability.

Comparative table of regulatory regimes

The key characteristics of the main regulatory regimes are presented below for ease of comparison:

Country / regime Main legislation Maximum penalty Extraterritorial scope Key feature
EU GDPR (2018) €20 million / 4% of annual global turnover Yes Broad data subject rights; DPO required for certain categories of controllers
Ukraine Law of Ukraine “On Personal Data Protection” Administrative liability No (GDPR alignment in progress) Administrative liability; Ombudsman as the supervisory authority; ongoing alignment with GDPR
US (federal) Sector-specific laws Depends on the applicable law Partially (state-level regulation) No single comprehensive federal law; regulation largely developed at the state level
California CCPA / CPRA Depends on the nature of the violation Yes (California residents) Enhanced consumer rights and control over personal data
United Kingdom UK GDPR + DPA 2018 £17.5 million / 4% of annual global turnover Yes Mandatory ICO registration and annual fee; enhanced consumer rights and control over personal data
Brazil LGPD (2020) Up to 2% of revenue in Brazil, capped at BRL 50 million per violation Yes Regulation largely based on the GDPR model
China PIPL (2021) Up to CNY 50 million or 5% of annual turnover Yes Data localization and government oversight; criminal liability for responsible individuals
Japan APPI Administrative sanctions, fines, and criminal liability for certain violations Yes Mandatory breach notifications; restrictions on cross-border data transfers

Detailed conditions and penalty thresholds depend on the nature of the violation and the specific jurisdiction.

Common trends and what they mean for businesses

Despite significant differences between jurisdictions, several common trends can be observed globally in personal data regulation:

  • Strengthening data subject rights: the rights to access, correct, delete, and port personal data are becoming standard features of most new data protection laws.
  • Expanded consumer rights to control personal data: new laws (including the CCPA/CPRA and VCDPA) increasingly grant consumers the right to opt out of the sale or sharing of their data, the right to correct inaccurate information, and the right to access collected information in a machine-readable format.
  • Extraterritoriality: an increasing number of laws apply to companies that process the data of residents of the relevant jurisdiction, regardless of where the company is incorporated.
  • Higher fines and stronger enforcement: maximum penalties are increasing — the GDPR has set a new benchmark followed by other jurisdictions, while regulators are making more active use of their enforcement powers.
  • Regulation of AI and algorithms: new laws (including the Colorado Privacy Act and the EU AI Act) are beginning to regulate not only data collection but also automated decision-making and profiling.
  • Accountability by default: companies are increasingly required to document and demonstrate compliance rather than simply declare it.

For Ukrainian businesses entering international markets, this means that personal data compliance is not a one-time exercise but an ongoing process of monitoring and adapting to legislative changes in each jurisdiction where the business operates.

GDPR and Ukraine’s Law “On Personal Data Protection”: key differences

For companies operating simultaneously in Ukraine and EU markets, it is important to understand the key differences between the two regulatory frameworks:

Criterion GDPR (EU) Law of Ukraine “On Personal Data Protection”
Scope Extraterritorial: applies to any company processing the data of EU residents Primarily territorial: applies to companies registered or operating in Ukraine
Fines Up to €20 million or 4% of global annual turnover Administrative liability; significantly lower penalties
Data subject rights Broad range of rights: access, rectification, erasure, data portability, right to object, and rights concerning automated decision-making Basic rights: access, rectification, and erasure. No right to data portability
DPO Mandatory for certain categories of controllers (public authorities, systematic monitoring, large-scale processing of sensitive data) Not provided for under the current law
Lawful bases for processing Six lawful bases explicitly defined by the Regulation Less detailed list; primarily focused on consent
Documentation requirements Extensive: records of processing activities, DPIAs, policies, and procedures Basic requirements for registration of personal data databases

Conclusion

Entering an international market means automatically becoming subject to different regulatory regimes — regardless of whether a company realizes this before its first transaction with a foreign client. A fine for violating the GDPR or CCPA can be many times greater than the value of a single contract. Therefore, personal data compliance is not a final step before entering a market but a prerequisite for entering it in the first place.

Three practical takeaways for Ukrainian businesses:

  • Determine which jurisdictions’ data you are actually processing before you start working with foreign clients. Having a client from the EU may already be sufficient to trigger the application of the GDPR.
  • Do not rely solely on Ukrainian legislation as a “safe harbor.” Ukraine’s Law “On Personal Data Protection” and the GDPR differ significantly, and compliance with one does not guarantee compliance with the other.
  • Build compliance as a system, not a collection of separate documents. Data mapping, an up-to-date Privacy Policy, procedures for responding to data subject requests, and a data breach response plan are the minimum framework for any company with international ambitions.

The overall trend is clear: requirements for transparency in data processing, protection of user rights, and corporate accountability will continue to become more stringent. Companies that establish personal data protection systems in advance gain not only legal security but also a competitive advantage in the eyes of international partners and clients.

 

Does your company process personal data of clients from the EU, the US, or other jurisdictions?

Barbashyn Law Firm can help you conduct a compliance audit covering the GDPR, CCPA, and other regulatory regimes, develop the necessary documentation, and establish effective personal data protection processes.

Share

FAQ

1. Does a Ukrainian company without an office in the EU need to comply with the GDPR?

2. What are the penalties for violating the GDPR?

3. What is the CCPA and does it apply to Ukrainian companies?

4. What is a DPO and when is one required?

5. How does the GDPR differ from Ukraine's Law “On Personal Data Protection”?

6. What is a cross-border transfer of personal data and what rules govern it?

7. Is a separate Privacy Policy required for each jurisdiction?

8. What is a “lawful basis” for processing data under the GDPR?

9. What are the main rights granted to data subjects under the GDPR?

10. How should a company start its personal data compliance process?

1. Does a Ukrainian company without an office in the EU need to comply with the GDPR?

Yes, if the company processes the data of individuals in the EU by offering them goods or services or monitoring their behavior online. The GDPR has extraterritorial scope and does not depend on where the company is registered. Having a website with prices in euros, serving customers from the EU, or using cookies to track the behavior of users in the EU may be sufficient for the GDPR to apply.

2. What are the penalties for violating the GDPR?

The GDPR provides for two levels of fines. Less serious violations (for example, breaches of requirements concerning consent or the processing of children's data) may result in fines of up to €10 million or 2% of the company's total worldwide annual turnover. More serious violations (including breaches of the basic principles, data subject rights, or rules on international data transfers) may result in fines of up to €20 million or 4% of the company's total worldwide annual turnover. Some of the largest enforcement cases include Meta Platforms — €1.2 billion (2023), TikTok — €345 million (2023), and Amazon — €746 million (2021).

3. What is the CCPA and does it apply to Ukrainian companies?

The CCPA (California Consumer Privacy Act) is a California state law governing consumer personal data protection. It applies to businesses that meet at least one of the following criteria: annual gross revenue above $26,625,000 (a threshold that is adjusted annually), processing the personal information of more than 100,000 California residents per year, or deriving more than 50% of annual revenue from selling or sharing personal information. If a Ukrainian company has customers in California and meets these criteria, the CCPA may apply to it.

4. What is a DPO and when is one required?

A DPO (Data Protection Officer) is a person responsible for overseeing compliance with GDPR requirements within an organization. Appointing a DPO is mandatory in three cases: (1) the company is a public authority or body; (2) its core activities involve regular and systematic monitoring of data subjects on a large scale; or (3) its core activities involve large-scale processing of special categories of personal data (such as health data, biometric data, or racial or ethnic data). In other cases, appointing a DPO is voluntary but recommended.

5. How does the GDPR differ from Ukraine's Law “On Personal Data Protection”?

The key differences are that the GDPR has extraterritorial scope, applying to entities that process the data of individuals in the EU, whereas Ukrainian law is primarily territorial in scope. The GDPR provides for significantly higher fines — up to €20 million or 4% of global annual turnover. It also grants data subjects a much broader range of rights, including the right to data portability and rights concerning automated decision-making, which are not currently provided for under Ukrainian law. The GDPR also requires more extensive documentation and mandates the appointment of a DPO for certain categories of controllers.

6. What is a cross-border transfer of personal data and what rules govern it?

A cross-border transfer of personal data is any transfer of, or access to, personal data across the borders of a particular jurisdiction. Under the GDPR, such transfers are permitted to countries recognized as providing an adequate level of data protection (based on a European Commission adequacy decision), or where appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other applicable safeguards. Unlike the EU, China requires government security assessment procedures for certain cross-border data transfers.

7. Is a separate Privacy Policy required for each jurisdiction?

Not necessarily. However, the Privacy Policy should reflect the rights of data subjects and requirements under the applicable laws. For EU customers, it should disclose the legal basis for processing under the GDPR; for California residents, it should provide information about the sale and sharing of personal information and the rights available under the CCPA. An effective approach is to use a single flexible Privacy Policy with dedicated sections for different jurisdictions.

8. What is a “lawful basis” for processing data under the GDPR?

The GDPR provides six lawful bases for processing personal data: (1) the data subject's consent; (2) performance of a contract; (3) compliance with a legal obligation; (4) protection of vital interests; (5) performance of a task carried out in the public interest; and (6) the legitimate interests pursued by the controller, taking into account the interests and rights of the data subject. Without one of these lawful bases, the processing of personal data is unlawful.

9. What are the main rights granted to data subjects under the GDPR?

The GDPR establishes a broad range of rights, including the right to access personal data, the right to rectify inaccurate information, the right to erasure (the “right to be forgotten”), the right to restriction of processing, the right to data portability (receiving data in a machine-readable format), the right to object to processing, and rights concerning automated decision-making and profiling. Data subjects may exercise these rights by contacting the controller directly.

10. How should a company start its personal data compliance process?

The recommended approach is to: (1) identify the jurisdictions whose residents' data you process; (2) conduct a personal data inventory (data mapping) to determine what data you collect, where it is stored, and who has access to it; (3) verify that a lawful basis exists for each type of processing; (4) update the Privacy Policy and consent forms; (5) establish procedures for responding to data subject requests and security incidents; and (6) appoint a DPO or designate a responsible person within the company, where necessary.

We use cookies to improve the performance of the site and enhance your user experience.

More information can be found in our Privacy Notice