Data Protection Matters
עברית|EN

Data Protection Matters

הגנת פרטיות: מהתיאוריה לפרקטיקה

מאמרים ומדריכים מקוריים, אינדקס חוקי הפרטיות של העולם וכלים חינמיים, לחיפוש וסינון במקום אחד.

התוכן נועד להעשרה ולעיון כללי, ואינו מהווה ייעוץ משפטי. אנו עושים מאמץ מרבי להבטיח את דיוק המידע אך איננו יכולים להתחייב לכך, ויש לאמת אותו תמיד מול המקורות הרשמיים (הערה משפטית מלאה מופיעה מטה).

מאגר הידע הבינלאומי

מאמרים, מדריכים ואינדקס חוקי הפרטיות של העולם. התוכן באנגלית, וניתן לחיפוש וסינון יחד עם התוכן הישראלי.

Articles

כלי חינמי

חיפוש ב-GDPR וב-EDPB

חיפוש בטקסט המלא של ה-GDPR, הסעיפים וההקדמות, יחד עם ההנחיות וההמלצות של ה-EDPB, מהמקורות הרשמיים.

Frameworks & Governance

Turn your DPIA into a business asset, not a box to tick

A Data Protection Impact Assessment done well is not paperwork. It is one of the clearest views of risk your organization will ever produce. Here is how to get there.

October 7, 2026 Read →
AI & Governance

Why Ethical AI Is an Engineering Problem, Not Just a Policy One

Ethical AI is not just about policy and regulation. It is fundamentally an engineering challenge. Learn why fairness, transparency, and security need to be treated with the same rigor as performance and reliability in the AI development lifecycle.

March 29, 2026 Read →
Global Regulations

Vietnam's New Data Privacy Frontier: A Comprehensive Guide to Law No. 91/2025/QH15

Vietnam is no longer just a manufacturing alternative; it has officially emerged as a mature technology hub with a rigorous legal framework to match. As of January 1, 2026, the new Law on Personal Data Protection is in full effect, introducing GDPR-style mandates, mandatory DPIAs, and aggressive revenue-based fines. Is your organization ready for the 'Brussels Effect' in Southeast Asia?

March 26, 2026 Read →
AI & Governance

Accountability in Motion: OpenAI Appeals and Age Assurance

This week features a major legal win for OpenAI as an Italian court canceled its €15 million fine, signaling a more mature phase in AI enforcement. Meanwhile, the UK ICO's penalty against Reddit underscores that "self-declaration" for age checks is no longer sufficient; platforms must implement robust age assurance. Across Europe, a growing push for "joined-up" regulation highlights that privacy, AI, and competition laws must now be managed as a single strategic ecosystem.

March 25, 2026 Read →
EU Data Strategy & GDPR

Guest Checkout: No Longer a Luxury, but a GDPR Requirement

The EDPB's Recommendations 2/2025 (published for consultation in December 2025) indicate that forcing users to create an account for one-time purchases is hard to justify under the GDPR. Unless strictly necessary for the contract, guest checkout should be the default. Personalization and administrative convenience do not justify mandatory registration. This shift pushes retailers to adopt "privacy by design" by offering guest modes to ensure data minimization and respect user choice.

December 17, 2025 Read →
Industry Spotlights

Simplifying the GDPR: The EU Digital Omnibus and EdTech Privacy

The EU's new "Digital Omnibus" aims to simplify GDPR and AI laws by refining personal data definitions and streamlining consent. Simultaneously, the EU Court is re-evaluating the US-EU data flow agreement, creating potential residency risks for global firms. In the US, the FTC's settlement with Illuminate Education over student data misuse underscores a shift toward aggressive enforcement in the EdTech sector, demanding stricter retention and security protocols for minors' data.

December 4, 2025 Read →
Industry Spotlights

Mandatory User Accounts: The EDPB Challenges Common E-commerce Practices

The EDPB's Recommendations 2/2025, published for public consultation, directly challenge the legality of mandatory user registration in e-commerce. This insight explores why the "business as usual" approach to online shopping is no longer defensible under the GDPR, and how retailers can move to a privacy-first checkout.

November 20, 2025 Read →
Industry Spotlights

The Hidden Ecosystem: Why Tracking Pixels are Your Biggest Legal Liability

Tracking pixels are leaking sensitive data from thousands of sites to tech giants. Meta faces legal pressure as regulators highlight "joint-controller" liability for site owners using these tools. Consequently, many organizations are switching to privacy-preserving, first-party analytics to reduce risk and restore trust.

November 7, 2025 Read →
EU Data Strategy & GDPR

The Right to be Forgotten: California's AB 656 and New GenAI Guidance

This week highlights California's new AB 656 law, which requires large social media platforms to offer a clear "Delete Account" option and to erase user data when an account is deleted, alongside the Delete Act's data broker deletion regime. Meanwhile, the EDPS issued guidance on Generative AI, stressing that GDPR principles like transparency and lawful basis apply fully to AI training and outputs. Lastly, a shift in cyber threats is noted: "silent breaches" involve long-term infiltration and slow data siphoning, requiring organizations to pivot from perimeter defense to proactive anomaly detection.

October 30, 2025 Read →
Industry Spotlights

Cross-Regulatory Synergy: The Digital Clearinghouse and Ethical AI in Hiring

This week's insights cover major shifts in data governance: the EU's move toward cross-regulatory coordination (Digital Clearinghouse 2.0), the launch of responsible AI standards for the education sector (K-20 collaboration), and a shift toward ethical AI in hiring. The key takeaway is that privacy and AI governance must be context-specific, requiring organizations to unify oversight across legal frameworks to protect consumers and students effectively.

October 23, 2025 Read →
Frameworks & Governance

Bridging the CISO-DPO Divide: Uniting Cybersecurity and Data Privacy

Tired of CISO-DPO friction? Learn how to transform cybersecurity and data privacy into a powerful, unified force for stronger data protection

June 23, 2025 Read →
Frameworks & Governance

Navigating the Data Maze: Understanding Processor, Controller, and Joint Controller Roles is Key to Your Data Strategy

Understanding who holds responsibility for personal data is a legal necessity under GDPR. The Data Controller decides the "why" and "how" of processing, while the Data Processor acts only on the controller's instructions. In some cases, Joint Controllers share decision-making. Clearly defining these roles in a Data Processing Agreement (DPA) is crucial for legal compliance, allocating liability in case of breaches, and building trust with customers and partners.

June 17, 2025 Read →
Global Regulations

Consent in the Digital Age: A Case Study of Meta's "Consent or Pay" Tactic

Consent is a fundamental concept in data privacy, serving as the linchpin that aligns personal autonomy with technological advancement. It is the mechanism through which individuals exercise control over their personal information, granting or withholding permission for organizations to collect, process, and share their data.

March 29, 2024 Read →
EU Data Strategy & GDPR

Navigating the Complexities of Data Processing Agreements

Data Processing Agreements (DPAs) are the bedrock of trust and compliance in the digital ecosystem, where personal data flows between various stakeholders. These agreements are not mere documents but are foundational to establishing a clear, structured, and legally binding relationship between data controllers and data processors.

March 17, 2024 Read →
Frameworks & Governance

The evolving role in the world of privacy protection: a symphony for the rights of data subjects

The world of data protection has evolved beyond a solitary endeavor. Enter Data Privacy Operations (DPOps), a harmonious assembly playing an endless symphony for the rights of data subjects.

March 10, 2024 Read →
Global Regulations

An In-Depth Look at China's Personal Information Protection Law (PIPL) and Its Comparison with GDPR

China's PIPL sets stringent rules for collecting and processing personal data, drawing many parallels to the GDPR. It grants individuals rights to access, correct, and delete data while imposing heavy fines for violations. Key differences include PIPL's specific focus on businesses within China and its unique consent requirements. This landmark law significantly impacts how global companies manage information, requiring strict adherence to principles like data minimization and security.

January 1, 2024 Read →
EU Data Strategy & GDPR

Guidelines for Ensuring Privacy of Health-Related Data

The Council of Europe's Recommendation CM/Rec(2019)2 provides a framework for protecting sensitive health data in the digital age. It emphasizes key principles: transparency, lawfulness, and fairness in data processing. Organizations must obtain explicit consent, implement "privacy by design," and ensure robust security measures. These guidelines balance the need for medical research with the fundamental right to individual privacy, ensuring public trust in healthcare technologies.

December 27, 2023 Read →
Frameworks & Governance

Elevating Security Standards: Embracing the Transition to ISO 27001:2022

ISO 27001:2022 updates the global standard for information security management. Key changes include a more risk-based approach, simplified control themes (Organizational, People, Physical, Technological), and 11 new controls like threat intelligence and cloud security. This version offers greater flexibility and addresses modern cyber threats. Transitioning helps organizations strengthen their security posture, ensure continuous improvement, and protect sensitive data in an evolving landscape.

December 2, 2023 Read →
Global Regulations

An In-Depth Look at South Africa's Protection of Personal Information Act (POPIA) and Its Comparison with GDPR

South Africa's POPIA regulates personal data processing with strict conditions on consent, security, and accuracy. While sharing core principles with GDPR, it has unique jurisdictional rules, different breach reporting timelines, and criminal penalties including imprisonment. Organizations must ensure compliance with eight key conditions, such as purpose limitation and data minimization, to avoid heavy fines and ensure lawful cross-border data transfers.

May 17, 2023 Read →
AI & Governance

The Importance of Responsible Use: An Overview of the Proposed AI Act

The proposed AI Act and the importance of responsible use of AI, including protecting privacy and aligning AI with human values and rights

April 16, 2023 Read →

Guides & Tools

Free tool

DPIA Questionnaire: the free EDPB tool

A complete Data Protection Impact Assessment built from the EDPB template. Work through controller details, lawfulness, necessity, risk scoring and the decision, all in your browser. Nothing is sent or stored; export and resume anytime.

Start the DPIA →

Privacy Regulations and Cloud Applications

Navigating privacy compliance in cloud-based, microservices-driven environments: data fragmentation, secure communication, vendor compliance, and privacy by design.

Download PDF

Safeguarding Privacy in eCommerce

Practical recommendations for e-commerce: understanding data flow, a comprehensive privacy policy, strong security, customer consent, and staying current with regulations.

Download PDF

Ensuring Privacy of Health-Related Data

An overview of the Council of Europe's Recommendation CM/Rec(2019)2 and key principles for the ethical, secure processing of health data.

Download PDF

Navigating Standard Contractual Clauses (SCCs)

SCCs for international transfers: common pitfalls, best practices, and why they must be tailored, with the Meta fine as a cautionary tale.

Download PDF

South Korea's Personal Information Protection Act (PIPA)

A comprehensive analysis of PIPA, its enforcement mechanisms, and how it compares with the GDPR.

Download PDF

China's Personal Information Protection Law (PIPL)

An overview of PIPL compared with the GDPR, and the rights and obligations it creates for individuals and businesses.

Download PDF

Responsible AI: Ethics, Data Protection and Governance

How responsible AI, fairness, transparency, accountability, privacy, aligns with data protection and governance, and how to get there.

Download PDF

Navigating the Complexities of DPAs

Why Data Processing Agreements matter for trust and compliance, and the practical steps to create and manage them.

Download PDF

Protecting HR Data

Guidelines for HR: transparency, limited collection, access controls, secure storage, and team education to protect employee and candidate data.

Download PDF

Embracing the Transition to ISO 27001:2022

Key updates in ISO 27001:2022, its risk-based approach and new controls, and how to transition to the new standard.

Download PDF

The DPO Role: Same Same, But Different

How the Data Protection Officer's role is shifting from compliance enforcer to strategic business partner.

Download PDF

South Africa's Protection of Personal Information Act (POPIA)

A comparison of POPIA with the GDPR: scope, consent, security, penalties, and what it means for organizations.

Download PDF

International Privacy Laws

Privacy laws around the world

Tap a highlighted country to open its overview, or browse the full list below.

Covered, opens overviewMarker (state or small country)Not covered yet
Australia

Privacy Act 1988

Australia's federal privacy law and the Australian Privacy Principles.

Brazil

LGPD

Lei Geral de Protecao de Dados (2020), Brazil's GDPR-inspired data protection law.

California, USA

CCPA / CPRA

California Consumer Privacy Act as amended by the CPRA: rights to know, delete, correct and opt out.

Canada

PIPEDA

Personal Information Protection and Electronic Documents Act.

China

PIPL

Personal Information Protection Law (2021): strict rules on processing and cross-border transfers.

European Union

GDPR

General Data Protection Regulation (2018), the EU's comprehensive privacy law and the global benchmark.

India

DPDP Act 2023

Digital Personal Data Protection Act, India's new consent-based framework.

Israel

Privacy Protection Law

Israel's Privacy Protection Law and Amendment 13, enforced by the PPA.

Japan

APPI

Act on the Protection of Personal Information.

Nigeria

NDPA

Nigeria Data Protection Act (2023).

Saudi Arabia

PDPL

The Personal Data Protection Law of the Kingdom of Saudi Arabia.

Singapore

PDPA

Singapore's Personal Data Protection Act.

South Africa

POPIA

Protection of Personal Information Act, South Africa's comprehensive privacy law.

South Korea

PIPA

Personal Information Protection Act, one of Asia's strictest privacy regimes.

Switzerland

nFADP

The revised Federal Act on Data Protection (2023).

Thailand

PDPA

Thailand's Personal Data Protection Act, modelled on the GDPR.

United Arab Emirates

PDPL

The UAE's federal Personal Data Protection Law.

United Kingdom

UK GDPR & DPA 2018

The UK's post-Brexit version of the GDPR, with the Data Protection Act 2018.

USA

HIPAA

Health Insurance Portability and Accountability Act: privacy and security of health data.

Vietnam

Law No. 91/2025/QH15

Vietnam's first comprehensive Personal Data Protection Law (2025).

We work hard to keep everything here accurate and current, but it may contain errors or omissions, and we make no warranty, express or implied, as to its accuracy or completeness. Everything on this page is a general reference, not legal advice, and using it does not create a lawyer-client or advisory relationship. Our articles and guides reflect the law at the time of writing, and this index of laws is not exhaustive. Each card opens our own plain-English overview, which is not the law and not binding; from there we link to the official source. Some countries publish the authoritative text only in their own language, so an English version may be an unofficial translation. Always rely on the official source, seek professional advice for your specific situation, and treat any reliance on this content as at your own risk.

לא נמצאו תוצאות. נסו מונח אחר.