Overview
A free reference and procedure guide for data protection and privacy law, starting with the UK, the EU and the US, and built to expand outward without a rewrite. Every record carries its depth tier, its sources and the date it was last verified.
What this is
Three content types sit inside the Atlas, and they answer different questions:
- Reference — what the law is: jurisdictions, instruments, sections, offences, exemptions.
- Procedure — what you do: SAR handling, breach notification, FOI response.
- Concepts — how to think: risk, governance, retention, lawful basis. Jurisdiction-neutral.
How it is kept honest
- Every Tier 1 instrument answers all ten asymmetry checklist points — the build fails if one is missing.
- Exemptions are recorded with their trigger conditions, never as bare names.
- Criminal liability is recorded separately from regulatory fines, because they are separate tracks.
- Unsettled legal questions are flagged as unsettled rather than resolved by picking a reading.
Jurisdictions
206 jurisdictions in the directory. 1 verified against sources; 112 seeded from the earlier prototype and clearly marked as unverified until someone checks them. Browse, search and filter the full directory →
Germany
Germany applies the GDPR (cross-refer instrument id gdpr) supplemented by the federal BDSG and 16 Land data protection acts.
United Kingdom
A single unified regime: the UK GDPR (the onshored Regulation (EU) 2016/679) read together with the Data Protection Act 2018 as one Keeling-schedule-style whole, with PECR 2003 as lex specialis for direct marketing and cookies.
Australia
Principal framework: Privacy Act 1988 (major 2024 amendments) (1988).
Austria
Principal framework: GDPR + Datenschutzgesetz (DSG) (2018).
Belgium
Principal framework: GDPR + Data Protection Framework Act 2018 (2018).
Brazil
Principal framework: LGPD (2018).
Instruments
Privacy Act 1988 (Australia)
Privacy Act 1988 (Cth), No. 119 of 1988, as amended by the Privacy and Other Legislation Amendment Act 2024 (No. 128 of 2024)
BDSG
BDSG of 30 June 2017 (BGBl. I p. 2097), as amended
revFADP (Switzerland)
Revised Federal Act on Data Protection (revFADP / nFADG), Switzerland
Codice Privacy
Decreto legislativo 30 giugno 2003, n. 196, as amended by d.lgs. 101/2018
COPPA
15 U.S.C. 6501-6506; 16 CFR Part 312
DPA 2018
Data Protection Act 2018, c. 12
DPA 2018 (IE)
Data Protection Act 2018 (No. 7 of 2018)
Digital Personal Data Protection Act (India)
Digital Personal Data Protection Act, 2023 (No. 22 of 2023), India; Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))
CCPA/CPRA
Cal. Civ. Code sec. 1798.100 et seq.
FCRA
15 U.S.C. 1681 et seq.
GDPR
Regulation (EU) 2016/679 (General Data Protection Regulation)
HIPAA
Pub. L. 104-191, as amended by the HITECH Act 2009; 45 CFR Parts 160 and 164
GLBA
Pub. L. 106-102, Title V; Regulation P, 12 CFR Part 1016; FTC Safeguards Rule, 16 CFR Part 314
Lei Geral de Proteção de Dados (Brazil)
Lei Geral de Proteção de Dados Pessoais, Lei No. 13.709/2018, Brazil
Loi 78-17
Loi n° 78-17 du 6 janvier 1978, as amended
LOPDGDD
Ley Orgánica 3/2018, de 5 de diciembre
PECR
SI 2003/2426
Personal Information Protection Law (China)
Personal Information Protection Law of the PRC
POPIA (South Africa)
Protection of Personal Information Act 4 of 2013, South Africa
PDPA 2012 (Singapore)
Personal Data Protection Act 2012 (No. 26 of 2012), Singapore, as amended by the PDP(A) Act 2020
UAVG
Uitvoeringswet AVG (2018)
UK GDPR
Regulation (EU) 2016/679 as retained and amended by the European Union (Withdrawal) Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419)
VCDPA
Va. Code sec. 59.1-575 et seq.
Procedures
Written as one archetype plus thin per-jurisdiction overrides — 2 archetype and 2 overrides so far. An override states only what differs.
Personal data breach notification (GDPR family)
How to detect, assess, record and (where required) notify a personal data breach under the EU/EEA GDPR.
Subject access requests — GDPR family
How a subject access request works anywhere the rules descend from Article 15 GDPR.
Personal data breach notification (UK)
UK deltas to the GDPR breach archetype.
Subject access requests — United Kingdom
The UK deltas from the GDPR-family SAR archetype, post-DUAA 2025.
Governance
The applied layer: what a piece of correspondence is actually asserting, and what it obliges the recipient to do. Written for both sides of the same letter — the person making the complaint and the officer answering it. Open the governance section →
Anatomy of a complaint
A realistic escalation letter taken apart paragraph by paragraph.
Making a complaint that lands
Structure, order, and the sentences that make delay measurable.
Handling one you have received
A first-hour checklist, and the three failures that escalate complaints.
Concepts
Depth tiers
What Tier 1, 2 and 3 mean, and why the tier is printed on every page rather than hidden in an editorial policy.
Sub-national patterns
Federated countries do not vary in one shape. Four distinct patterns, what each one means for where the law actually lives, and why "solve the US, solve them all" is wrong.
V1 scope and sequencing
The agreed v1 scope is UK + EU + US. Everything else stays at its current baseline and is labelled as such rather than padded out.
| Scope | Target depth | State |
|---|---|---|
| UK — DPA 2018 | Tier 1 | Published |
| UK — UK GDPR, PECR | Tier 1 | Next |
| EU — GDPR itself | Tier 1 | Next |
| US — California, then Virginia | Tier 1 | Planned |
| Germany (Pattern 3 stress test) | Tier 1 | Planned |
| EU — Ireland, France, Netherlands, Italy, Spain | Tier 1 | Planned |
| EU — remaining ~24 member states | Tier 2 | Planned |
| US — federal sectoral (HIPAA, GLBA, COPPA, FCRA) | Tier 1 | Planned |
| US — remaining ~16 state acts | Tier 2 | Planned |
Depth tiers
Tier 1
Full instrument profile: all ten asymmetry checklist points answered, offences and exemptions itemised with their conditions.
Tier 2
Status, principal law, regulator, breach rule, penalty figure, one source link.
Tier 3
Status, law name, regulator, source link only — a signpost to the primary source.