Data Protection Atlas
Static build · content collections

Overview

A free reference and procedure guide for data protection and privacy law, starting with the UK, the EU and the US, and built to expand outward without a rewrite. Every record carries its depth tier, its sources and the date it was last verified.

206
Jurisdictions
1
Verified against sources
23
Instruments profiled
4
Procedures

What this is

Three content types sit inside the Atlas, and they answer different questions:

  • Reference — what the law is: jurisdictions, instruments, sections, offences, exemptions.
  • Procedure — what you do: SAR handling, breach notification, FOI response.
  • Concepts — how to think: risk, governance, retention, lawful basis. Jurisdiction-neutral.

How it is kept honest

  • Every Tier 1 instrument answers all ten asymmetry checklist points — the build fails if one is missing.
  • Exemptions are recorded with their trigger conditions, never as bare names.
  • Criminal liability is recorded separately from regulatory fines, because they are separate tracks.
  • Unsettled legal questions are flagged as unsettled rather than resolved by picking a reading.

Jurisdictions

206 jurisdictions in the directory. 1 verified against sources; 112 seeded from the earlier prototype and clearly marked as unverified until someone checks them. Browse, search and filter the full directory →

Instruments

Privacy Act 1988 (Australia)

Tier 2

Privacy Act 1988 (Cth), No. 119 of 1988, as amended by the Privacy and Other Legislation Amendment Act 2024 (No. 128 of 2024)

BDSG

Tier 1

BDSG of 30 June 2017 (BGBl. I p. 2097), as amended

revFADP (Switzerland)

Tier 2

Revised Federal Act on Data Protection (revFADP / nFADG), Switzerland

Codice Privacy

Tier 2

Decreto legislativo 30 giugno 2003, n. 196, as amended by d.lgs. 101/2018

COPPA

Tier 1

15 U.S.C. 6501-6506; 16 CFR Part 312

DPA 2018

Tier 1

Data Protection Act 2018, c. 12

DPA 2018 (IE)

Tier 2

Data Protection Act 2018 (No. 7 of 2018)

Digital Personal Data Protection Act (India)

Tier 2

Digital Personal Data Protection Act, 2023 (No. 22 of 2023), India; Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))

CCPA/CPRA

Tier 1

Cal. Civ. Code sec. 1798.100 et seq.

FCRA

Tier 1

15 U.S.C. 1681 et seq.

GDPR

Tier 1

Regulation (EU) 2016/679 (General Data Protection Regulation)

HIPAA

Tier 1

Pub. L. 104-191, as amended by the HITECH Act 2009; 45 CFR Parts 160 and 164

GLBA

Tier 1

Pub. L. 106-102, Title V; Regulation P, 12 CFR Part 1016; FTC Safeguards Rule, 16 CFR Part 314

Lei Geral de Proteção de Dados (Brazil)

Tier 2

Lei Geral de Proteção de Dados Pessoais, Lei No. 13.709/2018, Brazil

Loi 78-17

Tier 2

Loi n° 78-17 du 6 janvier 1978, as amended

LOPDGDD

Tier 2

Ley Orgánica 3/2018, de 5 de diciembre

PECR

Tier 1

SI 2003/2426

Personal Information Protection Law (China)

Tier 2

Personal Information Protection Law of the PRC

POPIA (South Africa)

Tier 2

Protection of Personal Information Act 4 of 2013, South Africa

PDPA 2012 (Singapore)

Tier 2

Personal Data Protection Act 2012 (No. 26 of 2012), Singapore, as amended by the PDP(A) Act 2020

UAVG

Tier 2

Uitvoeringswet AVG (2018)

UK GDPR

Tier 1

Regulation (EU) 2016/679 as retained and amended by the European Union (Withdrawal) Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419)

VCDPA

Tier 1

Va. Code sec. 59.1-575 et seq.

Procedures

Written as one archetype plus thin per-jurisdiction overrides — 2 archetype and 2 overrides so far. An override states only what differs.

Governance

The applied layer: what a piece of correspondence is actually asserting, and what it obliges the recipient to do. Written for both sides of the same letter — the person making the complaint and the officer answering it. Open the governance section →

Concepts

V1 scope and sequencing

The agreed v1 scope is UK + EU + US. Everything else stays at its current baseline and is labelled as such rather than padded out.

Scope Target depth State
UK — DPA 2018 Tier 1 Published
UK — UK GDPR, PECR Tier 1 Next
EU — GDPR itself Tier 1 Next
US — California, then Virginia Tier 1 Planned
Germany (Pattern 3 stress test) Tier 1 Planned
EU — Ireland, France, Netherlands, Italy, Spain Tier 1 Planned
EU — remaining ~24 member states Tier 2 Planned
US — federal sectoral (HIPAA, GLBA, COPPA, FCRA) Tier 1 Planned
US — remaining ~16 state acts Tier 2 Planned

Depth tiers

Tier 1

Full instrument profile: all ten asymmetry checklist points answered, offences and exemptions itemised with their conditions.

Tier 2

Status, principal law, regulator, breach rule, penalty figure, one source link.

Tier 3

Status, law name, regulator, source link only — a signpost to the primary source.