DPDP, GDPR, CCPA/CPRA, US state laws, LGPD, and UAE PDPL all point in the same direction: people should be able to find, access, correct, delete, and control personal data without needing a lawyer to decode the process.
Coverage
India, EU/UK, California, US states, Brazil, and UAE / Dubai
Core rights
Access, deletion, correction, consent control, opt-out, portability, grievance
Product angle
Turn legal rights into request letters, response clocks, evidence, and follow-up workflows
Every privacy law has two sides: what a person can ask for, and what a company must do to answer properly. This page breaks each law into coverage, rights, deadlines, business obligations, limits, and the practical benefit for the customer.
A privacy right is only useful when the company can locate the person across product, billing, marketing, support, and HR systems.
Modern privacy laws care about safeguards, access control, retention, and auditability. The operational goal is not just sending a letter; it is keeping the evidence clean.
Deadlines, identity checks, exceptions, deletion outcomes, and opt-outs all need a record. That is where request tracking becomes more valuable than plain legal text.
Deadlines and rights vary. The practical pattern is consistent: identify the person, locate their data, honour the right, and keep proof.
Law
DPDP ActWho it protects
India and offshore processing tied to people in India
Response clock
Privacy Conduit uses a 30-day operational target from the shared jurisdiction pack; statutory rights mechanics depend on the phased commencement and Rules.
Most useful for
Gives Indian users a direct route to ask what is stored, why it is used, and who it is shared with
Law
GDPRWho it protects
European Economic Area and United Kingdom, with extraterritorial reach
Response clock
Without undue delay and generally within 1 month; complex requests can be extended by 2 more months with notice.
Most useful for
Lets individuals see the full picture: data held, purposes, recipients, retention, and sources
Who it protects
California plus a growing patchwork of US states
Response clock
Most consumer requests: 45 calendar days, with a possible 45-day extension after notice.
Most useful for
Turns ad-tech and data broker opacity into an actionable opt-out right
Who it protects
Federal PDPL: all UAE mainland entities and any org processing UAE-resident data. DIFC: ~8,844 active DIFC-incorporated firms. ADGM: ~12,671 Abu Dhabi Global Market licences.
Response clock
Federal PDPL and DIFC: 30 days. ADGM: 60 days (2 months) with 30-day extension. Privacy Conduit tracks all three clocks separately.
Most useful for
Federal PDPL creates a compliance baseline across 1.4M UAE mainland companies and is modelled to align with global standards
Law
LGPDWho it protects
Brazil, Brazilian residents, and services aimed at people in Brazil
Response clock
Confirmation can be simplified immediately; a clear and complete access statement is due within 15 days under Article 19.
Most useful for
Gives Brazilian users both access and explanation: origin, purpose, criteria, and sharing
India DPDP
Up to ₹250 crore per specified failure; ₹500 crore aggregate cap
Data Protection Board of India
EU / UK GDPR
€20 million or 4% of global annual revenue, whichever is higher
National DPAs (e.g. Ireland DPC, France CNIL)
US CCPA / CPRA
$7,500 per intentional violation; $2,500 per unintentional violation
California AG and California Privacy Protection Agency
Brazil LGPD
2% of Brazil revenue per infraction, capped at R$50 million
ANPD — Autoridade Nacional de Proteção de Dados
UAE PDPL
Up to AED 20 million for sensitive data violations; AED 5 million otherwise
UAE Data Office (federal); DIFC / ADGM commissioners for free zones
India's digital personal data framework for consent, safeguards, and Data Principal rights.
Who and where
India and offshore processing tied to people in India
Response clock
Privacy Conduit uses a 30-day operational target from the shared jurisdiction pack; statutory rights mechanics depend on the phased commencement and Rules.
Enforcement
Data Protection Board of India; penalties can reach INR 250 crore for specified failures.
What it covers
Digital personal data processed in India, and processing outside India when connected with offering goods or services to Data Principals in India.
Status
Enacted in 2023. The 2025 commencement notification brings provisions online in phases; Data Principal rights sections 11-17 are scheduled for May 13, 2027.
The benchmark privacy law for access, erasure, portability, accountability, and data protection by design.
Who and where
European Economic Area and United Kingdom, with extraterritorial reach
Response clock
Without undue delay and generally within 1 month; complex requests can be extended by 2 more months with notice.
Enforcement
EU supervisory authorities and the UK ICO; serious infringements can reach EUR 20 million or 4% of global annual turnover.
What it covers
Controllers and processors established in the EU/UK, plus organisations outside the region that offer goods or services to people there or monitor their behaviour.
Status
EU GDPR has applied since May 25, 2018. UK GDPR remains the UK framework after Brexit, with the ICO as the UK regulator.
A state-by-state privacy system built around knowing, deleting, correcting, opting out, and appealing.
Who and where
California plus a growing patchwork of US states
Response clock
Most consumer requests: 45 calendar days, with a possible 45-day extension after notice.
Enforcement
California Privacy Protection Agency, state attorneys general, and state-specific enforcement schemes.
What it covers
California residents under CCPA/CPRA when a covered for-profit business meets statutory thresholds; other states apply their own thresholds, exemptions, and covered-rights models.
Status
California CCPA took effect in 2020 and was expanded by CPRA in 2023. As of May 2026, comprehensive state privacy laws have been enacted in roughly 20 states.
Three legally distinct data protection regimes operating in parallel: Federal PDPL for mainland entities, DIFC DP Law for Dubai's financial centre, and ADGM DPR for Abu Dhabi's global market.
Who and where
Federal PDPL: all UAE mainland entities and any org processing UAE-resident data. DIFC: ~8,844 active DIFC-incorporated firms. ADGM: ~12,671 Abu Dhabi Global Market licences.
Response clock
Federal PDPL and DIFC: 30 days. ADGM: 60 days (2 months) with 30-day extension. Privacy Conduit tracks all three clocks separately.
Enforcement
UAE Data Office (Federal, AED 20M max fine), DIFC Commissioner of Data Protection (USD 50K per violation + private litigation), ADGM Commissioner (USD 28M per offense).
What it covers
Federal PDPL covers all mainland UAE processing and any processing of UAE-resident data globally. DIFC and ADGM are separate free zone regimes — DIFC and ADGM entities are explicitly excluded from Federal PDPL scope.
Status
Federal PDPL (Decree-Law No. 45 of 2021): Executive Regulations issued 2024, enforcement deadline January 2027. DIFC DP Law 2020: actively enforced since 2020; July 2025 amendment added private right of action. ADGM DPR 2021: moderately enforced.
Brazil's GDPR-inspired privacy law with a broad rights catalogue and a fast access deadline.
Who and where
Brazil, Brazilian residents, and services aimed at people in Brazil
Response clock
Confirmation can be simplified immediately; a clear and complete access statement is due within 15 days under Article 19.
Enforcement
ANPD; administrative fines can reach 2% of Brazilian revenue, capped at R$50 million per infraction.
What it covers
Processing carried out in Brazil, processing for offering goods or services to people in Brazil, or processing of personal data collected in Brazil.
Status
Effective since 2020/2021, enforced by Brazil's Autoridade Nacional de Protecao de Dados (ANPD).
Learn the rights you can exercise. Privacy Conduit helps you send privacy requests under the right law — in minutes.
Get started freeAssess which laws apply, intake requests, approve fulfillment workflows, and keep an audit trail for every decision.
Review business workflowFREQUENTLY ASKED