“Does this country have sub-national data protection law?” is the wrong question, because a yes covers at least four structurally different situations. Every jurisdiction record declares which pattern it follows, and the pattern decides what a sub-jurisdiction page even contains.
Pattern 1 — Patchwork, no floor
Example: the United States.
No general federal private-sector law. Each state’s comprehensive act is independently substantive — different thresholds, different rights, different enforcement — and a federal sectoral layer (HIPAA, GLBA, COPPA, FCRA) sits alongside, unrelated to the state layer. There is nothing to inherit from. This is the hardest shape to model: each sub-unit is a full instrument in its own right.
Pattern 2 — Floor with substitution
Example: Canada.
A federal default applies everywhere unless a province has passed its own “substantially similar” law, in which case the provincial law displaces the federal one entirely for intra-provincial private-sector activity. Structurally closer to Pattern 1 than to the EU — the provincial laws are independently substantive, not derogationsDerogationA permitted departure from a rule. The GDPR's opening clauses let member states legislate nationally in defined areas, so national acts are derogations from a shared text rather than independent statutes. from a shared text — but there is still a named default that applies where a sub-unit has not replaced it.
Pattern 3 — Uniform private law, devolved public sector or regulator
Examples: Germany, Switzerland, Mexico, Australia.
The consumer-facing law is one national statute, full stop. Sub-national variation is confined to which regulator has jurisdiction, to public-sector bodies only, or to one narrow sector such as health data. The substantive private-sector law never forks. Sub-units here get a regulator lookup table, not a duplicated country profile — which is what stops the model generating sixteen near-empty pages with nothing in them.
Pattern 4 — Fully unified
Examples: the United Kingdom, and most of the world.
No sub-national axis at all. Note that this can be true even where other law is devolved: in the UK, data protection is reserved while freedom of information is devolved in Scotland — the two diverge in exactly opposite directions, and assuming one from the other is a reliable way to get it wrong.
Why the distinction is load-bearing
It is tempting to build the hardest case (Pattern 1) and declare federated jurisdictions solved. They are not. Pattern 1 work validates Pattern 1 and, partially, the independent-substantive-sub-unit mechanics that Pattern 2 also needs. It does not validate Pattern 3, which is a different problem — jurisdiction-of-regulator and public/private split, not competing substantive rights — and needs its own check when a Pattern 3 country is profiled in depth.
The build order follows from that: prove the hard pattern on two deliberately different sub-units, then bank easy wins elsewhere, alternating so neither half of the scope races ahead of the other.