Privacy Regulation Compliance Guides
In-depth, article-by-article guides to the world's leading privacy regulations. Each guide explains exactly what your privacy policy must include — written for business owners, not lawyers.
GDPR Privacy Policy Guide
Complete Article 13 compliance: controller identity, DPO contact, six lawful bases, legitimate interests, recipients, international transfers with safeguards (SCCs, adequacy decisions, BCRs), retention periods, and all eight data subject rights — including the right to lodge a complaint with your local supervisory authority.
Key articles: Art. 5, 6, 7, 9, 13, 14, 15-22, 25, 27, 30, 33-34, 37, 44-49, 77
Applies to: Any organisation processing EU/UK resident data (territorial scope, Art. 3)
CCPA/CPRA Privacy Policy Guide
Complete CCPA compliance as amended by CPRA: the 12 statutory categories of personal information, sources and business purposes, right to know, right to delete, right to opt out of sale/sharing, right to correct, right to limit use of sensitive PI, "Do Not Sell or Share" link requirements, financial incentive notices, purpose limitation, data minimisation, and annual metrics disclosure.
Key sections: Civ. Code 1798.100-.199.100 (CCPA); 1798.140(v), 1798.140(ae), 1798.121 (CPRA additions)
Applies to: For-profits with $25M+ revenue, 100K+ CA residents' data, or 50%+ revenue from data sales
CalOPPA Privacy Policy Guide
Seven specific CalOPPA requirements: categories of PII collected, categories of third parties, user access and review process, change notification mechanism, effective date, and the two-part Do Not Track signal disclosure. Includes a full comparison table showing the differences between CalOPPA (transparency) and CCPA (consumer rights).
Key sections: Cal. Bus. & Prof. Code 22575-22579
Applies to: Any commercial website collecting PII from CA residents — no revenue or data volume threshold
PIPEDA Privacy Policy Guide
All 10 fair information principles (Schedule 1): accountability, identifying purposes, meaningful consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Plus CASL anti-spam overlap, Quebec Law 25 obligations, BC PIPA and Alberta PIPA provincial variations, and a PIPEDA-vs-GDPR comparison.
Key sections: PIPEDA S.C. 2000, c. 5, Schedule 1 Principles 1-10; Quebec Law 25 (2022); BC PIPA; Alberta PIPA
Applies to: Private-sector organisations collecting personal information in commercial activity
Quick Comparison: Which Regulation Applies to You?
Each privacy regulation has different triggers, and your business may need to comply with multiple regimes simultaneously. Here is a summary of when each applies:
| Regulation | Trigger | Privacy Policy Required? | Consumer Rights Provided? |
|---|---|---|---|
| GDPR (EU/UK) | Offering goods/services to or monitoring EU/UK residents | Yes — Art. 13/14 | Eight rights (Art. 15-22) |
| CCPA/CPRA | $25M+ revenue OR 100K+ CA residents' data OR 50%+ revenue from data sales | Yes — notice at collection + privacy policy | Right to know, delete, opt-out, correct, limit sensitive PI |
| CalOPPA | Any commercial website collecting PII from CA residents | Yes — must be conspicuously posted | Limited: access to review/change PII |
| PIPEDA | Collecting personal information in commercial activity in Canada | Yes — openness principle (Principle 8) | Access and correction (Principle 9) |
Most online businesses need to comply with two or more of these regulations. Use our free AI privacy policy generator to create a single comprehensive policy that satisfies all applicable laws.