Privacy Regulation Compliance Guides

In-depth, article-by-article guides to the world's leading privacy regulations. Each guide explains exactly what your privacy policy must include — written for business owners, not lawyers.

EU / UK

GDPR Privacy Policy Guide

Complete Article 13 compliance: controller identity, DPO contact, six lawful bases, legitimate interests, recipients, international transfers with safeguards (SCCs, adequacy decisions, BCRs), retention periods, and all eight data subject rights — including the right to lodge a complaint with your local supervisory authority.

Jurisdiction: European Economic Area + United Kingdom
Key articles: Art. 5, 6, 7, 9, 13, 14, 15-22, 25, 27, 30, 33-34, 37, 44-49, 77
Applies to: Any organisation processing EU/UK resident data (territorial scope, Art. 3)
California (CPRA)

CCPA/CPRA Privacy Policy Guide

Complete CCPA compliance as amended by CPRA: the 12 statutory categories of personal information, sources and business purposes, right to know, right to delete, right to opt out of sale/sharing, right to correct, right to limit use of sensitive PI, "Do Not Sell or Share" link requirements, financial incentive notices, purpose limitation, data minimisation, and annual metrics disclosure.

Jurisdiction: California, USA
Key sections: Civ. Code 1798.100-.199.100 (CCPA); 1798.140(v), 1798.140(ae), 1798.121 (CPRA additions)
Applies to: For-profits with $25M+ revenue, 100K+ CA residents' data, or 50%+ revenue from data sales
California

CalOPPA Privacy Policy Guide

Seven specific CalOPPA requirements: categories of PII collected, categories of third parties, user access and review process, change notification mechanism, effective date, and the two-part Do Not Track signal disclosure. Includes a full comparison table showing the differences between CalOPPA (transparency) and CCPA (consumer rights).

Jurisdiction: California, USA
Key sections: Cal. Bus. & Prof. Code 22575-22579
Applies to: Any commercial website collecting PII from CA residents — no revenue or data volume threshold
Canada

PIPEDA Privacy Policy Guide

All 10 fair information principles (Schedule 1): accountability, identifying purposes, meaningful consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Plus CASL anti-spam overlap, Quebec Law 25 obligations, BC PIPA and Alberta PIPA provincial variations, and a PIPEDA-vs-GDPR comparison.

Jurisdiction: Canada (federal) + provincial substantially-similar laws
Key sections: PIPEDA S.C. 2000, c. 5, Schedule 1 Principles 1-10; Quebec Law 25 (2022); BC PIPA; Alberta PIPA
Applies to: Private-sector organisations collecting personal information in commercial activity

Quick Comparison: Which Regulation Applies to You?

Each privacy regulation has different triggers, and your business may need to comply with multiple regimes simultaneously. Here is a summary of when each applies:

Regulation Trigger Privacy Policy Required? Consumer Rights Provided?
GDPR (EU/UK) Offering goods/services to or monitoring EU/UK residents Yes — Art. 13/14 Eight rights (Art. 15-22)
CCPA/CPRA $25M+ revenue OR 100K+ CA residents' data OR 50%+ revenue from data sales Yes — notice at collection + privacy policy Right to know, delete, opt-out, correct, limit sensitive PI
CalOPPA Any commercial website collecting PII from CA residents Yes — must be conspicuously posted Limited: access to review/change PII
PIPEDA Collecting personal information in commercial activity in Canada Yes — openness principle (Principle 8) Access and correction (Principle 9)

Most online businesses need to comply with two or more of these regulations. Use our free AI privacy policy generator to create a single comprehensive policy that satisfies all applicable laws.

Generate Your Privacy Policy Now