International Privacy Resources M-Z || Privacy Rules M-Z | Privacy Laws M-Z | Privacy Regulations M-Z
March 20th, 2013
Welcome! Please comment and leave me a note telling me what you like and what you'd like to see more of. Sign up to my RSS Feed!International Privacy Laws, Rules, Regulations and Resources
International Privacy Laws, Rules, Regulations and Resources
M to Z
As of November 11, 2011, Breach notification laws have moved to their
own page, at www.arielsilverstone.com/resources/collection-of-breach-notification-laws
- Macedonia / Македонија / Makedonija / Maqedonia(Not a part of Greece. Former Yugoslav Republic, CE, CE185)
Directorate for Personal Data Protection (DZLP, Macedonian) Law on Personal Data Protection (Consolidated) (Macedonian PDF) Law Amending the Law on Protection of Personal Data no. 135/11 (Macedonian PDF) Law Amending the Law on Protection of Personal Data no. 124/10 (Macedonian PDF) Law Amending the Law on Protection of Personal Data no. 103/08 (Macedonian PDF) Law on Personal Data Protection no. 7 / 05) (Macedonian PDF) - Madagascar / Madagasikara
- None Found
- Malawi / Dziko la Malaŵi / 马来西亚 / Măláixīyà / மலேசியா / Malēciyā
- None Found
- Maldives / Divehi Rājje ge Jumhuriyyā
- None Found
- Mali
- None Found
- Malta (Member EU, Schengen, CE)
- Office of the Data Protection Commissioner (Note: Many Legal Notices Available Here)
- Data Protection Act (CAP 440, PDF)
- Malaysia / மலேசியா / 马来西亚
- Personal Data Protection Bill 2010 (PDPA, PDF)
- Marshall Islands /Aelōn̄ in M̧ajeļ (in Free Association with the United States)
- Mauritania/ Mauritanie / Mūrītāniyā
- None Found
- Mauritius / Maurice / Moris
- Mexico / United Mexican States / Estados Unidos Mexicanos / México (Member OECD)
- Federal Law on The Protection of Personal Information in Possession of the Private Sector
- States of Mexico:
Aguascalientes Baja California Baja California Sur Campeche Chiapas Chihuahua Coahuila de Zaragoza Colima Durango Guanajuato Guerrero Hidalgo Ignacio de la Llave Jalisco México (Distro Federal) Michoacán de Ocampo Morelos Nayarit Nuevo León Oaxaca Puebla Querétaro Quintana Roo San Luis Potosí Sinaloa Sonora Tabasco Tamaulipas Tlaxcala Veracruz Yucatán Zacatecas - Moldova (Member CE)
Centrului Naţional pentru Protecţia Datelor cu Caracter Personal (National Center for Personal Data Protection) Law Nr. 17-XVI of 15.02.2007 on personal data protection Law on Personal Data Protection (new redaction) no.133 from 08 July 2011 (shall come into force at 14.04.2012) - Monaco / Múnegu / Mónegue (Not member of Schengen, but generally administered as if it were, CE)
- Commission de Contrôle des Informations Nominatives (Commission of Control of Personal Information, French)
- Protection of Personal Data Law (1.165, PPDL, French PDF)
- Mongolia / Монгол улс / Mongol uls
- None Found
- Montenegro / Црна Гора / Crna Gora
- None Found
- Morocco / al-Maġrib / ⵎⴰⵖⵔⵉⴱ / Maɣrib
- None Found
- Myanmar / Pyi-daung-zu Myan-ma Naing-ngan-daw / Burma (Despotic Regime)
- None Found
- Nauru / Naoero
- None Found
- Nepal / नेपाल / Nepāl
- None Found
- New Zeland / Aotearoa (Member OECD, CPEA)
Office of the Privacy Commissioner / Te Mana Matapono Matatapu Health Information Privacy Code (HIPC, PDF) Telecommunications Information Privacy Code (TIPC, PDF) Privacy Act Summary Privacy Act Also Includes - The Dependent Territory of Tokelau
- Parts of the Antarctic Ross Ice Shelf
- Nicaragua
- None Found
- Niger / Nijar
- None Found
- Nigeria / Nijeriya / Naigeria / Niiseriya / Naìjírìà
- National Health Bill (PDF)
- North Korea / Hanguk (Despotic Regime)
- None Found
- Norway / Norge / Noreg (Member OECD, CE, CE108, Schengen)
Datatilsynet (The Date Inspectorate, in Bokmål (Norsk)) Personal Data Act (Translated PDF) Royal Regulations on the Processing of Personal Data (Translated PDF) Personal Health Data Filing System Act (Including Processing of Personal Health Data, translated) - Oman
- None Found
- Pakistan / Pākistān
- None Found
- Palau / Pelwe / Beluu / Belau
- None Found
- Panama / Panamá
- None Found
- Papua-New Guinea / Papua Niugini
- None Found
- Parguay / Paraguái
- National Secretariat of State Reform
- Peru / Perú / Piruw
- Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual (INDECOPI / National Institute for the Defense of Competition and Intellectual Property Protection
- Ley que Regula las Centrales Privadas de Información de Riesgos y de Protección al Titular de la Información Ley Nº 27.489 / Law Regulating the Privacy of Information Risk and Protection of Information Owner Law No. 27.489 – no Source found.
- Phillipines / Pilipinas / Filipinas
- NONE
- Poland / Polska (Member EU, OEC, CE, CES 108), Schengen, CEEP)
- Generalnego Inspektora Ochrony Danych Osobowych (GIODO) / Inspector General for Personal Data Protection (in Polish)
- Protection of Personal Data Law (Polish PDF)
- Portugal / Pertual (Member EU,OECD, Schengen, CE)
Law Creating CNPD (Portuguese PDF) Comissão Nacional de Protecção de Dados(CNPD, National Commission for Protection of Data, in Portuguese) Law 67/1998 – Protection Personal Data and Information (Portuguese PDF) Law 32/2008 – Retention of Electronic Communications Data (Portuguese PDF) Law 41/2004 – Protection of Personal Data in Electronic Communications (Portuguese PDF) Law 109/1991 – Information Crimes (Portuguese PDF) Portugal also controls: - The Azores
- Madiera
- Qatar / Dawlat Qaṭar
- None Found
- Romania / România (Member EU, Schengen (not implemented), CE, CE185)
- Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (The National Supervisory Authority For Personal Data Processing) (Romanian)
- Notification Guide (Romanian)
- Law no. 677/2001 (Translated PDF)
- Law no. 682/2001 (Translated PDF)
- Law no. 102/2005 (Translated PDF)
- Law no. 55/2005 (Translated PDF)
- Law no. 506/2004 (Translated PDF)
- Emergency Ordinance no. 36/2007 (Translated PDF)
- Law no. 298/2008 (Translated PDF)
- Russia /Россия /
Российская Федерация / Russian Federation / Rossyia (Member CE, but NOT Ratified ETS 108)Federal Act 24-FZ – Information, Informatization and Information Protection (Translated, now replaced by 149-FZ) информации, информационных технологиях и о защите информации / Federal Act 149-FZ – Information, Information Technologies and Protection of Information (Russian) Federal Act 152-FZ – “On Personal Data” (Russian PDF) Federal Act 15-FZ – “On Communication” Criminal Code Article 108: Violation of the Secrecy of Correspondence, Telephone Conversations, Postal, Telegraphic and Other Messages (Translated) - Includes the Following Federal Subject areas:
- Includes the Following Federal Subject areas:
- Republics (areas with right to form their own constitution):
Adygea Altai Bashkortostan Buryatia Chechnya Chuvashia Dagestan Ingushetia Kabardino-Balkaria Kalmykia Karachay-Cherkessia Karelia Khakassia Komi Mari El Mordovia North Ossetia-Alania Sakha Republic Tatarstan Tuva Udmurtia - Provinces (Oblasts):
Amur Arkhangelsk Astrakhan Belgorod Bryansk Chelyabinsk Chita Irkutsk Ivanovo Kaliningrad Kaluga Kemerovo Kirov Kostroma Kurgan Kursk Leningrad Lipetsk Magadan Moscow Murmansk Nizhny Novgorod Novgorod Novosibirsk Omsk Orenburg Oryol Penza Pskov Rostov Ryazan Sakhalin (note: disputed with Japan) Samara Saratov Smolensk Sverdlovsk Tambov Tomsk Tver Tula Tyumen Ulyanovsk Vladimir Volgograd Vologda Voronezh Yaroslavl - Territories (Krais):
Altai Kamchatka Khabarovsk Krasnodar Krasnoyarsk Perm Primorsky Stavropol Zabaykalsky - Federal Cities:
- Moscow
- St. Petersberg
- Autonomous Oblast:
- Jewish Autonmous Oblast / Евре́йская
автоно́мная о́бласть / Yevreyskaya avtonomnaya oblast / ייִדישע אווטאָנאָמע געגנט
- Jewish Autonmous Oblast / Евре́йская
- Autonomous Districts (Okruga):
Chukotka Khanty–Mansi Nenets Yamalo-Nenets
- Republics (areas with right to form their own constitution):
- Includes the Following Federal Subject areas:
- Includes the Following Federal Subject areas:
- Rwanda
- None Found
- Saint Kitts and Nevis / Federation of Saint Christopher and Nevis / Saint-Christophe et Nevis
- None Found
- Saint Lucia / Sainte Lucie
- None Found
- Saint Vincent and the Grenadines
- None Found
- Samoa / German Samoa / Western Samoa / Malo Sa’oloto Tuto’atasi o Samoa / Sāmoa
- None Found
- San Marino (Member CE, but NOTRatified ETS 108)
- São Tomé and Príncipe / São Tomé e Príncipe
- None Found
- Saudi Arabia / as-Saʿūdiyyah / Roubah El-Hali (Despotic Regime)
- None Found
- Senegal / Sénégal
- None Found
- Serbia / Србија / Szerbia / Serbija (Member CE)
- None Found
- Seychelles / Sesel
- None Found
- Sierra Leon
- None Found
- Singapore / Singapura / 新加坡 / சிங்கப்பூர் / Chiṅkappūr
Electronic Commerce Code for the Protection of Personal Information and Communications of Consumers of Internet Commerce (source not found) Model Data Protection Code for the Private Sector Infocomm Development Authority of Singapore (IDA) - Slovakia / Slovensko / Szlovákia (Member EU, OECD, Schengen, CE, CEEP)
- Úrad na Ochranu Osobných Údajov (Office for Personal Data Protection, Slovak)
- Act 428/2002 – Protection of Personal Data (Translated PDF)
- Slovenia / Slovenija / Szlovénia (Member EU, Schengen, CE, CE185)
- Informacijski Pooblaščenec (IP-RS, Information Commissioner, Sloven)
- Personal Data Protection Act (Translated)
- Solomon Islands
- None Found
- Somalia / Soomaaliya / As-Sūmāl / Somalo (No Effective Government)
- None Found
- South Sudan
- None Found
- South Africa / / Suid-Afrika / Sewula Afrika / Zantsi Afrika / Ningizimu Afrika / Afrika-Borwa / Afrika Dzonga / Afurika Tshipembe (CE185)
- None Found
- South Korea / Chosŏn / 대한민국 / 大韓民國 / Daehanminguk (Member OECD)
- Spain / España / Espanya / Espainia / Espanha (Member EU, OECD, Schengen, CE)
- Agencia Española de Protección de Datos (AEPD, in Spanish)
- Protection of Personal Data Law (Translated PDF)
- Law 34/2002 – Information Society Services and Electronic Commerce (Translated PDF)
- Law 41/2002 – Regulating Patient Data (Translated PDF)
- Law 32/200 – State Telecommunications Act (Translated PDF)
- Law 62/2003 – Modifying Data Protection Regulations (Translated PDF)
- Regions and Districts:
- Datuak Babesteko Euskal Bulegoa / Agencia Vasca de Protección de Datos / Basque Agency for Protection of Data
- Ley 2/2004, de Ficheros de Datos de Carácter Personal de Titularidad Pública y de Creación de la Agencia Vasca de Protección de Datos (Law 2/2004 Regarding Protection of Data of Personal Nature, of Public Access, and The Creation of the Basque Agency of Data Protection, translated PDF)
- Ley Orgánica 15/1999, de Protección de Datos de Carácter Personal (LOPD, Law of Protection of Data of Personal Nature, in Spanish)
- Agencia Catalana de Protección de Datos / Catalan Agency for Protection of Data)
- Ley 5/2002, de la Agencia Catalana de Protección de Datos (Law (creating) of The Catalan Agency of Protection of Data, in Spanish)
- Agencia de Protección de Datos de la Comunidad de Madrid / Community of Madrid Agency for Protection of Data, (APDCM)
- Ley Orgánica 15/1999, de Protección de Datos de Carácter Personal (Law of The Protection of Data of Personal Character, Spanish PDF)
- Ley 8/2001, de Protección de Datos de Carácter Personal en la Comunidad de Madrid (Protection of Data of Personal Character in the Community of Madrid, in Spanish)
- Datuak Babesteko Euskal Bulegoa / Agencia Vasca de Protección de Datos / Basque Agency for Protection of Data
- Independent Cities:
- Ceuta
- Melilla / Tamelilt
- Independent Places:
- Islas Chafarinas
- Peñón de Alhucemas
- Peñón de Vélez de la Gomera
- Independent Provinces:
- Balearic Islands / Illes Balears / Islas Baleares, including:
- Cabrera
- Formentera
- Ibiza
- Majorca
- Minorca / Menorca
- Canary Islands / Comunidad Autónoma de Canarias, including:
- Alegranza
- El Hierro
- Fuerteventura
- Gran Canaria
- La Gomera
- La Graciosa
- La Palma
- Lanzarote
- Montaña Clara
- Tenerife
- Balearic Islands / Illes Balears / Islas Baleares, including:
- Sri Lanka / Ceylon / ශ්රී ලංකා / இலங்கை /Ilaṅkai / Shrī Laṁkā (Despotic Regime)
- None Found
- Sudan (Despotic Regime)
- None Found
- Suriname / Dutch Guiana
- None Found
- Swaziland / Umbuso weSwatini (Despotic Regime)
- None Found
- Sweden / Sverige (Member EU, OECD, Schengen, CE)
- SvenskaDatainspektionen (Swedish Data Inspection Board, in Swedish)
- Personal Data Act (PDA)
- Credit Information Act (In Swedish)
- Debt Collection Law (In Swedish) (Relevant here)
- Patient Data Act (Swedish PDF)
- Telecommunication Privacy (In Swedish)
- Swiss Confederation / Switzerland / Schweiz / Suisse / Svizzera / Svizra / Helvetica (Member OECD, Schengen, CE)
- Der Eidgenössische Datenschutz- und Öffentlichkeitsbeauftragte (EDÖB) / Le Préposé fédéral à la protection des données et à la transparence (PFPDT) / L’Incaricato federale della protezione dei dati e della trasparenza (IFPDT) / Federal Data Protection and Information Commissioner (FDPIC) Federal Act on Data Protection (DSG / LPD / FADP, translated)
- Ordinance on the Federal Act (Translated)
- Les Commissaires Suisses à la Protection des Données / Die Schweizerischen Datenschutzbeauftragten / The Cantonal Privacy Commissioners’ Association (Privatim, or “Privately”, In French and German)
- Cantons:
- Beauftragte für Oeffentlichkeit und Datenschutz des Kantons Aargau / Publicity and Privacy Officer for the Canton of Aargau(German)
- Datenschutz-Kontrollorgan des Kantons Appenzell Ausserrhoden / Data Protection Control (board) of the Canton Appenzell Ausserrhoden (Outer Rhoden)
- Datenschutzaufsicht des Kantons Appenzell Innerrhoden / Data Protection Supervisor of the Canton Appenzell Innerrhoden (Inner Rhoden)
- Datenschutzbeauftragte des Kantons Basel-Landschaft / Data Protection Supervisor of Canton Basel-County (German)
- Datenschutzbeauftragter des Kantons Basel-Stadt / Data Protection Supervisor of the canton of Basel-City (German)
- Datenschutzbeauftragter des Stadt Bern / Data Protection Supervisor of the State of Bern (German and French)
- Autorité de
surveillance du Canton de Friborg en Matière de Protection des Données / Authority of Surveillance and Master of Protection of Data of the Canton of Friborg (Free Castle) (German or French) - Commission de contrôle de l’informatique de l’Etat de Genève / Commission of Control of Information for the State of Geneva (French)
- Datenschutzbeauftragter des Kantons Glarus / Data Protection Supervisor of the Canton of Glarus (German)
- Datenschutzbeauftragter der Kantonalen Verwaltung des Kantons Graubünden / Data Protection Administration Supervisor of the Canton of Graubünden (Grey Grison) (German)
- Jura Commission Cantonale de la Protection des Données Jura / Cantonal Commission of Protection of Data, Jura (French)
- Datenschutzbeauftragter des Kantons Luzern / Data Protection Supervisor of the Canton of Lucerne (German)
- Autorité de Surveillance en Matière de Protection de la Personnalité du Canton de Neuchâtel; / Authority on the Surveiliance Regrading the Matter of Protection of People in the Neuchatel Canton (French)
- Datenschutzbeauftragter des Kantone Schwyz, Obwalden und Nidwalden / Supervisor of Data Protection of the Cantons of Schwyz, Oldforest and Newforest (almost-German)
- Datenschutzbeauftragte des Kantons St. Gallen / Data Protection Supervisor of the Canton of St.
Gallen (German) - Datenschutzbeauftragter des Kantons Schaffhausen / Data Protection Supervisor of the Canton of Schaffhausen
- Informations- und Datenschutzbeauftragter des Kantons Solothurn / Information and Data Protection for the Canton of Solothurn (German)
- Datenschutzbeauftragter des Kantons Thurgau / Data Protection Supervisor of the Canton of Thurgau
- Incaricato della Protezione dei Dati del Republica e Cantone Ticino / Data Protection Officer of the Republic and Canton of Ticino (Italian)
- Datenschutzbeauftragter des Kantons Uri / Data Protection Supervisor of the Canton of Uri (German)
- Commission Cantonale de la Protection des Données, Valais / Cantonal Commission of Protection of Data Canton of Valais
- Préposé à la Protection des Données du Canton de Vaud / Clerk of Data Protection of the Canton of Vaud
- Loi Sur la Protection des Données Personnelles (411, March 2007, PDF, in French)
- Datenschutzbeauftragter des Kantons Zug / Data Protection Supervisor of the Canton of Zug (Train) (German)
- Datenschutzbeauftragter des Kantons Zürich / Data Protection Supervisor of the Canton of Zurich (German)
- Municiplaties:
- Datenschutzaufsicht der Gemeinde Belp / Data Protection Supervisor of the Community of Belp
- Datenschutzaufsicht der Gemeinde Berne / Data Protection Supervisor of the Community of Bern
- Datenschutzbeauftragter der Einwohnergemeinde Steffisburg / Data Protection Supervisor of the Residential Community of Steffisburg
- Datenschutzaufsicht der Stadt Thun / Data Protection Supervisor of the City of Thun
- Datenschutzberater der Stadt Uster / Data Protection Preacher (policy maker) of the City of Uster
- Syria / Sūriyah (Despotic Regime, Regime Change in Progress)
- None
- None
- Taiwan 台灣 / Táiwān / Formosa / Republic of China
- Computer-Processed Personal Data Protection Law (Translated PDF)
- Enforcement Rules (Translated PDF)
- Tajikistan / Тоҷикистон / Tojikiston
- None Found
- Tanzania (Including Tanganyika and Zanzibar)
- Thailand / ประเทศไทย
- Tibet བོད་ / Bod / 西藏 /Xīzàng (under Chinese control)
- None Found
- Togo / République Togolaise
- None Found
- Tonga / Pule’anga Fakatu’i ‘o Tonga
- None Found
- Trinidad and Tubegu
- None Found
- Tunisia / Tunisie / Tunis / Tūnisīyah (Despotic Regime)
- Loi Organique Relative à la Protection des Données Personnelles (Personal Data Protection Law, no source found)
- Turkey / Türkiye (Member OECD, CE)
- None Found
- Turkmenistan / Türkmenistan / Turkmenia / Туркмения (Despotic Regime)
- None Found
- Tuvalu / Ellice Islands
- None Found
- Uganda
- None Found
- Ukraine / Ucrania / України (Despotic Regime) (CE)
- Law On Information (Translated PDF)
- Law on Data Protection in Information Systems (Translated PDF)
- Includes the Crimea
- United Arab Emirates
- None Found Nationally
- Includes:
- Abu Dhabi
- Ajman
- Dubai (Note: these laws were created under the authority of the Dubai International Financial Center, DIFC)
- Data Protection Law 2006 (it is called “2007″, no longer available, replaced the 2004 law)
- Data Protection Law of 2012 (PDF, replaced the 2006/7 law)
- Dubai International Financial Centre Authority
- Fujairah
- Sharjah
- Ras al-Khaimah
- Umm al-Quwain
- United Kingdom of Great Britain and Northern Ireland / Teyrnas Unedig Prydain Fawr a Gogledd Iwerddon / An Rìoghachd Aonaichte na Breatainn Mhòr agus Èirinn a Tuath / Ríocht Aontaithe na Breataine Móire agus Thuaisceart Éireann / Unitit Kinrick o Great Breetain an Northren Ireland / Ruwvaneth Unys Breten Veur hag Iwerdhon Gledh (Member OECD, EU, CE, Schengen (only partially implemented))
- Data Protection Act Information commissioner’s Office
- Co-administered territories:
- Anguilla
- Overseas Territories
- Bermuda
- Diego Garcia (leased to the United States Government)
- Gibraltar (Member EU)
- Montserrat
- Turks and Caicos (Member EU)
- Uruguay / República Oriental del Uruguay
- Uzbekistan / O‘zbekiston / Ўзбекистон
- None Found
- Vanuatu
- None Found
- Vatican (Holy See) / Vaticana / Vaticano
- None Found
- Venezuela / República Bolivariana de Venezuela (Despotic Regime)
- None Found
- Viet Nam / Việt Nam (Despotic Regime)
- None Found
- Yemen
- None Found
- Zambia
- Telecommunications (Consumer Protection) Regulations
- Zimbabwe (Despotic Regime)
- None Found