GDPR gets all the attention, but global companies face privacy regulations across dozens of jurisdictions. Brazil's LGPD, China's PIPL, South Africa's POPIA, and Singapore's PDPA each have distinct requirements that affect data enrichment operations. Many of these laws have extraterritorial reach, they apply if you're processing data about residents, regardless of where your company is based.
This guide covers major privacy frameworks beyond GDPR and how they can affect data enrichment activities. Before applying it to a market, confirm the official law, regulator, effective date, covered data and people, exemptions, and current implementing guidance for that jurisdiction.
The Global Privacy Landscape
Privacy regulation has proliferated rapidly. The IAPP Global Privacy Law and DPA Directory tracks legislation and regulators across jurisdictions, but each entry still needs verification against the applicable official source. Important differences include:
Key Regulatory Patterns
- GDPR-influenced: Many laws (LGPD, UK GDPR, POPIA) closely follow GDPR structure
- Consent-heavy: Some jurisdictions (China, much of Asia) emphasize consent more than GDPR
- Data localization: Several countries require data to remain within borders (China, Russia, Indonesia)
- Sector-specific: Some have distinct rules for different industries (healthcare, financial)
- Enforcement maturity: Laws exist but enforcement varies dramatically by jurisdiction
Extraterritorial Application
Most modern privacy laws apply to foreign companies that:
- Offer goods or services to residents in the jurisdiction
- Monitor behavior of residents in the jurisdiction
- Process personal data of residents (regardless of where processing occurs)
Americas: Beyond the United States
Brazil: LGPD (Lei Geral de Proteção de Dados)
Brazil's LGPD is South America's most significant privacy law, modeled closely on GDPR.
LGPD Key Requirements
- Data protection officer: Controllers generally designate a data protection officer, but qualifying small processing agents are exempt under Article 11 of ANPD Resolution No. 2. An exempt organization that does not appoint one must still provide a channel for data-subject requests.
For data enrichment, LGPD's legitimate interest basis works similarly to GDPR, you can enrich B2B data without consent if the interest is legitimate, necessary, and balanced against data subject rights. However, Brazil's ANPD (national authority) has been more prescriptive about legitimate interest assessments than some EU DPAs.
Argentina: PDPA
Argentina's Personal Data Protection Act predates GDPR but has been updated. Argentina has an EU adequacy decision, making data transfers relatively straightforward.
- Consent emphasis: More consent-dependent than GDPR for many processing activities
- Financial data: Extra protections for financial information
- Cross-border: EU adequacy simplifies transfers
Canada: PIPEDA and Provincial Laws
Canada's federal PIPEDA applies to commercial activities, but provinces can have substantially similar laws:
- Quebec: Law 25 (phased in 2023-2025) adds GDPR-like requirements including privacy impact assessments
- British Columbia/Alberta: Provincial private sector privacy acts
- Federal reform: Bill C-27 died when Parliament was prorogued in January 2025; PIPEDA modernization remains on the agenda but has no passed replacement yet
Mexico: LFPDPPP
Mexico's Federal Law on Protection of Personal Data Held by Private Parties:
- Privacy notice: Detailed notice requirements before collecting data
- Consent tiers: Different consent requirements for different data types
- ARCO rights: Access, Rectification, Cancellation, Opposition
- Financial data: Heightened protections
Asia-Pacific: Complex and Varied
China: PIPL (Personal Information Protection Law)
China's PIPL, effective November 2021, is one of the world's strictest privacy laws with significant implications for data enrichment.
PIPL Critical Requirements
PIPL materially restricts data enrichment involving Chinese residents. Key considerations:
- Consent requirements: More emphasis on consent than legitimate interest
- Transfer restrictions: Getting data out of China for enrichment is heavily regulated
- Government access: Authorities have broad data access rights
- Data minimization: Strong emphasis on collecting only necessary data
Japan: APPI (Act on Protection of Personal Information)
Japan's APPI, materially amended in 2022, has EU adequacy status:
- Pseudonymized data: Specific rules enable analytics on pseudonymized data
- Cross-border: Adequacy with EU; other transfers require consent or equivalent protection
- Cookies: 2022 amendments regulate cookies as personal information in some cases
South Korea: PIPA
South Korea's Personal Information Protection Act, amended in 2023:
- Consent emphasis: Strong consent requirements, especially for sensitive data
- Pseudonymization: Well-developed framework for pseudonymized data use
- Data combination: Specific rules for combining datasets
- Cross-border: EU adequacy status achieved in 2024
Singapore: PDPA
Singapore's Personal Data Protection Act is business-friendly while providing protection:
| Aspect | PDPA Approach | Enrichment Impact |
|---|---|---|
| Legal basis | Consent, legitimate interest, business improvement | Legitimate interest supports B2B enrichment |
| Consent exceptions | Broad business purposes exception | Publicly available data easier to use |
| Cross-border | Comparable protection standard | Transfers relatively flexible |
| Do Not Call | Separate DNC registry for marketing | Check before outbound marketing |
India: DPDP Act
India's Digital Personal Data Protection Act (2023) is the country's first complete privacy law:
- Consent-centric: Notice and consent are primary legal basis
- Legitimate use: Limited exceptions for specified legitimate uses
- Cross-border: Transfers allowed except to blacklisted countries
- Data localization: Government can mandate for certain data types
- Significant data fiduciary: Extra obligations for large processors
India's approach is consent-heavy, which may complicate B2B data enrichment operations.
Thailand: PDPA
Thailand's Personal Data Protection Act closely follows GDPR:
- GDPR structure: Six legal bases including legitimate interest
Indonesia: PDP Law
Indonesia's Personal Data Protection Law (2022):
- Data localization: Strategic sectors may require local storage
- Consent requirements: Explicit consent emphasis
- Cross-border: Requires comparable protection or binding rules
Australia: Privacy Act
Australia's Privacy Act with Australian Privacy Principles (APPs):
- APPs framework: 13 principles governing data handling
- Cross-border: Reasonable steps to ensure overseas compliance
- Reform pending: Significant amendments expected from Privacy Act Review
- Spam Act: Separate marketing consent requirements
Europe: Beyond GDPR
UK GDPR
Post-Brexit, the UK has its own GDPR version:
- Substantial similarity: Largely mirrors EU GDPR
- EU adequacy: The EU renewed UK adequacy in 2025, so EU-to-UK transfers remain straightforward for now
- ICO guidance: Sometimes differs from EU interpretations
- Reforms: The Data (Use and Access) Act 2025 adjusts UK data protection rules; divergence from the EU remains modest so far
Switzerland: nFADP
Switzerland's revised Federal Act on Data Protection (effective September 2023):
- GDPR alignment: Closely aligned with GDPR
- Cross-border: Adequacy list similar to EU
Middle East and Africa
South Africa: POPIA
South Africa's Protection of Personal Information Act:
POPIA Key Features
- GDPR-influenced: Similar structure with conditions for lawful processing
- Legitimate interest: Available as processing ground
UAE: Federal Data Protection Law
The UAE's federal data protection law and DIFC/ADGM regulations:
- DIFC: Dubai International Financial Centre has own GDPR-like law
- ADGM: Abu Dhabi Global Market has separate data protection regulations
- Consent focus: Strong emphasis on consent for processing
Saudi Arabia: PDPL
Saudi Arabia's Personal Data Protection Law:
- Cross-border: Requires adequate protection determination
- Enforcement: SDAIA oversees compliance
Nigeria: NDPA
Nigeria's Data Protection Act (2023), which replaced the earlier NDPR regulation:
- Legal bases: Consent plus agreement, legal obligation, important interest, public interest, and legitimate interest
- Regulator: The Nigeria Data Protection Commission (NDPC) enforces the Act
How Do Cross-Border Data Transfers Work?
Through one of three routes: an adequacy decision between the two jurisdictions, contractual safeguards like standard clauses, or an exception such as explicit consent. Getting enriched data across borders means picking the right mechanism for each corridor:
Adequacy Decisions
Some jurisdictions have mutual recognition:
| From | Adequate Destinations | Notes |
|---|---|---|
| EU | UK, Japan, South Korea, Argentina, Canada (commercial), others | US requires Data Privacy Framework |
| UK | EU/EEA, many EU-adequate countries | Adequacy bridge maintained |
| Japan | EU (mutual) | Supplementary rules apply |
| South Korea | EU (mutual, 2024) | New adequacy status |
Standard Contractual Clauses
Most jurisdictions accept some form of contractual safeguards:
- EU SCCs: Widely used, some non-EU countries accept
- UK IDTA: UK's international data transfer agreement
- China SCC: CAC-published standard agreement for outbound transfers
- ASEAN MCCs: Model contractual clauses for ASEAN transfers
Data Localization Requirements
Some jurisdictions restrict data from leaving:
- Vietnam: Certain data categories require local storage
How Do You Manage Compliance Across Multiple Jurisdictions?
Start with a GDPR-level baseline everywhere, then layer country-specific requirements on top for the markets you sell into. Trying to run 20 separate compliance programs fails; one program with regional add-ons scales. Clean, well-documented data helps too, since validated records with known provenance are far easier to defend than data of unknown origin:
Layered Compliance Framework
- Baseline layer: Implement GDPR-level protections globally as minimum standard
- Regional layer: Add requirements for major regions (APAC, LATAM, MENA)
- Country layer: Address specific requirements for high-priority markets
- Exception handling: Processes for markets with unusual requirements
Data Inventory Requirements
Maintain records of:
- Data origins: Where personal data comes from (which jurisdictions)
- Processing locations: Where data is stored and processed
- Data flows: How data moves between jurisdictions
- Vendor locations: Where enrichment providers process data
- Legal bases: Documented basis for each jurisdiction
Consent Management
For jurisdictions requiring consent:
- Granular collection: Capture consent for specific purposes
- Withdrawal mechanism: Enable easy consent withdrawal
- Audit trail: Maintain evidence of consent
Vendor Due Diligence
For data enrichment vendors:
- Processing locations: Know where vendor processes data
- Subprocessors: Understand downstream data flows
- Contractual coverage: Ensure DPAs cover relevant jurisdictions
- Certifications: ISO 27001, SOC 2, jurisdiction-specific certifications
Jurisdiction-Specific Enrichment Guidance
High-Restriction Jurisdictions
Where extra caution is needed:
| Jurisdiction | Key Restriction | Enrichment Approach |
|---|---|---|
| China | Cross-border transfer limits | Use local vendors; security assessment for transfers |
| Russia | Data localization | Store and process locally; limited enrichment options |
| India | Consent requirements | Ensure proper consent for B2C; watch for localization rules |
| Indonesia | Sector-specific localization | Assess sector applicability; use local processing |
Moderate Jurisdictions
GDPR-like but with variations:
- Brazil: Legitimate interest works; document DPIA; mind transfer mechanisms
- South Africa: Similar to GDPR; register Information Officer
- Thailand: GDPR approach works; ensure adequate transfer basis
- UAE: Consent-focused; free zone rules differ from federal
Business-Friendly Jurisdictions
Relatively straightforward for enrichment:
- Singapore: Business improvement exceptions; pragmatic enforcement
- UK: GDPR familiar; possible future flexibility
- Canada: Reasonable purposes standard (except Quebec)
Staying Current
Privacy law changes rapidly. Key monitoring strategies:
Regulatory Tracking
- DPA announcements: Follow data protection authorities in key markets
- IAPP resources: International Association of Privacy Professionals tracking
- Law firm alerts: International privacy practice newsletters
- Vendor updates: Data enrichment vendors should flag regulatory changes
Periodic Review
- Annual assessment: Review compliance posture for each jurisdiction
- Market entry: Full compliance review when entering new markets
- Major law changes: Update processes when significant amendments pass
- Enforcement trends: Adjust risk assessment based on enforcement patterns
Frequently Asked Questions
How does Brazil's LGPD affect data enrichment?
Start with the ANPD's official LGPD guidance and current ANPD materials. Map the record type, purpose, source, parties, transfer route, retention period, and request process before approving an enrichment workflow.
What are the key requirements of China's PIPL for data enrichment?
Use the official PIPL text published by China's Ministry of Industry and Information Technology and current regulator measures for the actual data flow. Document the people covered, data categories, purpose, recipient, storage location, transfer path, and deletion process rather than relying on a global summary.
How do Southeast Asian privacy laws differ from GDPR?
Do not treat Southeast Asia as one privacy regime. Identify the country, regulator, data categories, source, recipient, transfer route, and current implementing rules, then compare that result with the GDPR text provision by provision.
What is the best approach to multi-jurisdictional data compliance?
Maintain one inventory that records jurisdiction, source, purpose, fields, recipients, storage, transfer route, retention, and request handling for each workflow. Attach the current regulator source and review date to each country decision so a later update can be traced.
Is technographic data enrichment subject to GDPR compliance?
Inspect the complete record rather than the field label. Compare the dataset with the definition of personal data in GDPR Article 4, including whether the technology field sits beside an identified or identifiable person.
Do I need consent to enrich B2B contact data internationally?
The “B2B” label does not answer the question across countries. Record the person's jurisdiction, source, fields, purpose, recipient, channel, and transfer route, then compare that workflow with the current text and regulator guidance for that market.
Need help with your data?
We'll quote a real project from a real sample. Send a slice of your CRM and we'll have numbers back the same week.
See What We'll FindAbout the Author
Rome Thorndike is Verum's founder. He shipped ML systems inside Azure at Microsoft, then learned the sales side at Salesforce, then ran revenue teams at Snapdocs and Datajoy. Most of his Verum opinions come from breaking the same problems on the other side of the table.