Which countries offer the best protection for personal data?

Estimated reading time: 4 minutes

Summary

Data protection is a common concern in all countries worldwide. The amount of data generated is constantly growing, as organizations today use it to accelerate their development, enabling agile processes and achieving better performance. Given this, the great value of data today is undeniable, which consequently poses risks regarding the indiscriminate and improper use of data. 

Considering the need to protect this data, specific laws began to emerge to regulate the subject, as in the case of Brazil, where the General Data Protection Law (LGPD) was created, which will come into effect in August 2020. 

Brazilian law was entirely inspired by the GDPR, legislation that covers all member countries of the European Union. However, in addition to these, there are other countries in the world that have specific legislation on the subject; see some of them below: 

European Union

The GDPR (General Data Protection Regulation) regulates data protection in all countries belonging to the European Union. The legislation came into effect in May 2018; since then, European citizens have the right to know what information companies are collecting about them and for what purposes, in addition to other rules that impose effective data protection on companies that process their data, under penalty of a fine of 2% to 4% of their annual turnover. 

Japan

Japan's first data protection law, the APPI, was created in 2003, but was recently updated in 2015. The new rules resulting from the update came into effect in the country in 2017, a year before the European GDPR. Companies outside of Japan may also face sanctions if they do not handle Japanese citizens' data properly.

APPI distinguishes between two types of data: personal information, such as names and addresses, and information requiring special care, such as medical data and criminal records. In Japan, citizens can also request the review and deletion of their data if they wish. Penalties for companies in extreme cases include fines and imprisonment.

United States

There is no single data protection law in the United States. Each state is responsible for its own rules. One initiative that stands out is the California Consumer Privacy Act (CCPA). Californian legislation comes into effect in 2020, and companies will have to account for data collected since January 2019. The CCPA is more permissive than the GDPR, for example, allowing the collection (and sale) of data from teenagers without parental permission.

The law does not apply to any company, only those that: collect personal information from consumers; determine the purpose and means of processing personal information; do business in the State of California; and meet one or more of the following requirements:

  • Have annual gross revenue exceeding $25 million;
  • Purchase, receive, sell, or share, for commercial purposes, personal data of 50 or more California residents, properties, or devices;
  • Have 50% or more of your annual revenue derived from the sale of personal data of California residents.

Comply with Privacy Tools

Argentina

Argentina has had personal data protection laws since 1994, putting it ahead of other Latin American countries. According to the European Commission, Argentina and Uruguay are the only countries in Latin America with adequate levels of personal data protection. Current Argentine legislation protects personal data stored on all processing platforms, whether public or private.

Citizens can also access their information in public databases, but they do not need to consent to its collection in this case. Collection for company databases is conditional upon the consent of the data subject. This authorization is not necessary when the registration is limited to name, identity, profession, date of birth, and address.

Brazil

As previously mentioned, Brazilian legislation, known as the General Data Protection Law (LGPD), will come into effect in August 2020, meaning that all Brazilian companies must adapt to this new legal obligation, adopting measures to protect the personal data of data subjects. In Brazil, penalties for non-compliance with the law can include fines of up to 2% of annual revenue, with a ceiling of R$ 50 million for each infraction, in addition to other sanctions such as public disclosure of the infraction and others.

Compliance with these laws

There is no doubt that data protection will be the biggest global concern in the coming years. The new legislation mentioned above requires organizations to prepare and modify their culture and the way personal data has been handled until now; user privacy must now be understood as a standard. 

Therefore, organizations will face a long journey to adapt and comply with these new parameters. Privacy Tools is a Privacy Tech company, a privacy management platform that aims to offer solutions to simplify and facilitate this journey. Contact Us Learn more about our solutions and how we can help your organization. 

About the Author

Meet the author of this article.

  • We are a Privacy and Personal Data Protection Management, GRC, and ESG solution provider. We help companies build responsible businesses.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also