GDPR Beyond Borders: Why Your Data Privacy Rules Don't End at the EU

Let’s unpack the global data privacy maze—and why harmonisation might finally be on the horizon. Europe’s data privacy rulebook has become the world’s most influential regulatory export.

PHILOSOPHYTECHNOLOGYSOCIETY

André Maia

7/28/20266 min read

Imagine this: You’re a startup in São Paulo, building an app for European users. You’ve never set foot in the EU. Yet, if you mishandle someone’s data, you could face fines of up to €20 million—or 4% of your global revenue.

This isn’t hypothetical. It’s the reality of the GDPR’s extraterritorial reach.

Since its launch in May 2018, Europe’s data privacy rulebook has become the world’s most influential regulatory export. But here’s the catch: the rest of the world hasn’t caught up uniformly. What happens when GDPR meets America’s fragmented laws, China’s PIPL, or Brazil’s LGPD?

Let’s unpack the global data privacy maze—and why harmonisation might finally be on the horizon.

Why GDPR Applies Even If You’re Not in Europe

The GDPR establishes a robust framework for data protection with clear guidelines on where the regulation applies. Primarily enforced within the European Union (EU) and the European Economic Area (EEA), its influence extends far beyond those borders.

Article 3 of the GDPR specifies that the regulation governs any data processing that targets individuals residing within the EU—irrespective of the organization’s physical location. This extraterritorial effect means that a company based in São Paulo, Tokyo, or San Francisco must comply with GDPR obligations if it offers goods or services to, or monitors the behaviour of, individuals in the EU.

Furthermore, the GDPR imposes strict rules on data transfers outside the EU/EEA. Companies must ensure that the level of data protection in the receiving country effectively matches that guaranteed by the GDPR. Inadequate protections may result in substantial fines—up to €20 million or 4% of global annual turnover—plus significant reputational damage.

To facilitate lawful transfers, several mechanisms are available, such as Standard Contractual Clauses (SCCs) and adequacy decisions by the European Commission. These measures bridge the gap between EU standards and those in other jurisdictions.

Key takeaway: If your business touches EU residents’ data in any way, GDPR compliance isn’t optional—it’s mandatory, regardless of where you’re headquartered.

The Regulatory Maze: GDPR vs. CCPA vs. PIPL vs. Everyone Else

The landscape of data privacy regulations varies dramatically across regions, each shaped by distinct cultural, economic, and political contexts. Here’s how the major players stack up:

🇪🇺 Europe: The Gold Standard

In the EU, the GDPR serves as a comprehensive framework prioritising user consent, data minimisation, and transparency. Since its enactment, it has generated over €2 billion in cumulative fines as of 2024, demonstrating supervisory authorities’ serious enforcement stance.

🇺🇸 United States: Fragmented by Design

The U.S. lacks a unified federal data privacy law equivalent to the GDPR. Instead, it relies on sector-specific federal laws and an expanding network of state-level regulations:

  • California (CCPA/CPRA): Strengthened in 2023, grants consumers the right to opt out of data sales—a notable shift from earlier assumptions about U.S. leniency

  • Virginia, Colorado, Connecticut: Have enacted similar state-level privacy laws

  • Federal landscape: Still evolving, with various proposed bills stalled in Congress

The result is a patchwork where a company’s obligations depend heavily on which state its users reside in.

🇧🇷 Brazil: Following the European Model

Brazil’s Lei Geral de Proteção de Dados (LGPD), effective from September 2020, draws significant inspiration from the GDPR. It grants comparable rights to data subjects and imposes analogous penalties—demonstrating how GDPR principles are being adopted well beyond European borders.

🇨🇳 China: Strict and Getting Stricter

China’s Personal Information Protection Law (PIPL), enacted in 2021, establishes rigorous controls on cross-border data transfers and has been described as one of the world’s most demanding privacy regimes. It requires separate consent for sensitive data and mandates government security assessments for certain outbound transfers.

🇯🇵 Japan & 🇰🇷 South Korea: Converging Toward Europe

Japan’s Act on the Protection of Personal Information (APPI), substantially amended in 2020, received an adequacy decision from the European Commission, enabling mutual data flows. South Korea’s Personal Information Protection Act (PIPA) represents one of the stricter frameworks in the region.

🇿🇦 Africa: An Emerging Landscape

South Africa’s Protection of Personal Information Act (POPIA) became fully enforceable in 2022. Kenya, Nigeria, and Ghana have also enacted comprehensive frameworks, reflecting growing recognition of data privacy as a fundamental right across the continent.

What This Means for Multinational Companies

This regulatory patchwork creates substantial challenges for companies operating globally. The inconsistencies increase legal risks and operational complexity. As firms adapt to disparate regulations, the challenge lies in harmonising their data handling practices to meet both regional requirements and international standards—all while maintaining consumer trust.

When Data Leaves the EU: The Tricky Business of Cross-Border Transfers

Article 44 of the GDPR establishes crucial guidelines governing how personal data can be transferred outside the European Union. For organisations operating in multiple jurisdictions, this provision ensures that EU citizens’ fundamental rights aren’t compromised when their data is processed in countries with varying levels of privacy protection.

Under Article 44, any transfer of personal data to a non-EU country depends on the receiving country’s ability to guarantee an adequate level of data protection. The European Commission can issue adequacy decisions for countries deemed to possess safeguards comparable to those in the EU. As of early 2024, adequacy decisions cover approximately 15 jurisdictions, including Japan, South Korea, the United Kingdom, and Argentina.

The Schrems II Earthquake

Achieving adequacy status involves a lengthy assessment considering political, legal, and cultural differences. The 2020 Schrems II ruling by the Court of Justice of the European Union illustrates just how fragile these arrangements can be.

The ruling invalidated the EU-U.S. Privacy Shield framework, finding that U.S. surveillance laws did not provide sufficient protection for EU data subjects. This created significant uncertainty for transatlantic data flows until the EU-U.S. Data Privacy Framework was adopted in July 2023—a reminder that even established mechanisms can be overturned overnight.

Transfer Mechanisms at a Glance

The Cost of Compliance

Organizations often face delays and increased costs adapting operations to meet Article 44 requirements. Between conducting Transfer Impact Assessments, implementing supplementary safeguards, and monitoring legislative changes in destination countries, cross-border data management has become a specialised discipline unto itself.

The evolving landscape adds another layer of complexity—companies must stay vigilant to ensure their transfer mechanisms remain compliant as laws shift beneath them.

Is a Global Privacy Standard Actually Possible?

The increasing interconnectivity of the digital economy has intensified challenges around data privacy. While the GDPR delineates clear territorial limitations, these restrictions inadvertently create vulnerabilities. Businesses operating across borders face regulatory discrepancies that amplify risks of data breaches and misuse.

The Loophole Problem

Privacy advocates have increasingly called for universal data privacy standards to establish a cohesive regulatory framework. Fragmented regional rules, despite their protective intent, sometimes create opportunities for regulatory arbitrage—companies relocating data processing operations to jurisdictions with weaker protections, undermining robust frameworks like the GDPR.

Emerging technologies compound this problem. The rise of artificial intelligence and machine learning introduces new questions about data processing for model training, automated decision-making, and profiling. The EU’s AI Act, alongside ongoing GDPR enforcement, illustrates how overlapping regulations create additional compliance burdens without necessarily resolving cross-border tensions.

Existing Initiatives Worth Watching

Several initiatives point toward potential convergence:

  • Convention 108+ — The Council of Europe’s modernised convention provides an international instrument for data protection, open to accession by non-member states

  • OECD Privacy Guidelines — Updated in 2013, promoting common principles among member countries

  • APEC Cross-Border Privacy Rules — A voluntary framework facilitating data flows among Asia-Pacific economies

Such cooperative efforts could lead to more robust frameworks strengthening data protection for individuals regardless of where they live. This approach would foster an environment where businesses can thrive while prioritising consumer privacy rights—enhancing protection effectiveness while mitigating exploitation risks from regulatory disparities


The Road Ahead

The GDPR has established itself as a transformative force in global data protection, shaping regulatory developments far beyond European borders. However, the current patchwork of national and regional regulations creates persistent challenges—for businesses and consumers alike.

While full harmonisation remains aspirational, incremental convergence through bilateral agreements, mutual recognition frameworks, and shared enforcement cooperation offers practical pathways forward. As the digital economy evolves—with AI, cloud computing, and cross-platform integration reshaping data flows—the need for coherent international standards will only intensify.

The future of data privacy depends on balanced cooperation among governments, industry stakeholders, and civil society. Ensuring that individual rights remain protected in an increasingly interconnected world isn’t just a regulatory challenge. It’s a societal imperative.

What do you think? Are we moving toward genuine global convergence on data privacy, or will regional fragmentation persist indefinitely? If you work in compliance, legal, or tech, I’d love to hear about the real-world challenges your team faces.

Want to dive deeper? Check out these resources:

a close up of a toy standing in a maze
a close up of a toy standing in a maze
a group of people standing next to each other
a group of people standing next to each other
highway in desert
highway in desert

contato@andresmaia.com

©2026