What privacy laws around the world have in common

A woman partially hides behind a large white paper sheet indoors, looking directly at the camera

Photo by Gustavo Fring

Privacy compliance can feel especially difficult when your business works across different countries. The GDPR, UK GDPR, Australian Privacy Act, New Zealand Privacy Act, CCPA and other US state laws all use their own terminology, rules and thresholds.

A business reading several of these laws can easily come away with the impression that it needs a completely different privacy program for every location.

The details certainly matter, but the foundations are more consistent than they first appear. Major privacy frameworks repeatedly return to the same practical questions: What personal information do you hold? Why do you need it? What have you told people? Who can access it? How long will you keep it? What happens when someone asks about it or something goes wrong?

The OECD privacy principles were the first internationally agreed set of privacy principles and have helped shape privacy legislation and policy in countries around the world. Similar themes can now be seen across the GDPR, UK GDPR, Australian Privacy Principles, New Zealand Privacy Act and other major privacy frameworks.

Understanding these shared principles gives a business a practical foundation. It does not replace checking the laws that apply in each country, but it makes that work much easier to organise.

Start by understanding the personal information you hold

Most privacy obligations become difficult when a business does not have a clear picture of its information.

Personal information tends to build up through normal work. It may sit in customer relationship management systems, email inboxes, accounting software, shared drives, employee records, support platforms and old spreadsheets. External providers may also store copies in cloud platforms, marketing systems, payroll services and backups.

This matters because a business cannot explain, protect, correct or delete information it cannot locate. It may also struggle to respond confidently when a customer, employee or regulator asks how information is being handled.

A common problem is focusing only on the most obvious customer database. This can leave recruitment records, former employee files, website enquiries, exported reports and information held by service providers outside the picture.

A sensible starting point is a simple personal information inventory. It does not need to document every individual record. It should identify the main categories of information the business handles and answer a few practical questions:

  • What information is being collected?
  • Whose information is it?
  • Why does the business need it?
  • Where is it stored?
  • Who can access it?
  • Which external providers receive it?
  • How long is it normally kept?

This inventory becomes the reference point for almost everything that follows.

Collect information for a clear business purpose

Privacy laws generally expect businesses to know why they are collecting personal information and to limit collection to what is relevant for that purpose.

The language differs between countries. The GDPR and UK GDPR include purpose limitation and data minimisation among their core principles. Australian privacy law addresses whether collection is reasonably necessary for an organisation’s functions or activities. New Zealand’s privacy principles similarly address the purpose and manner of collection.

In everyday business processes, extra information can be collected without much thought. A form may have been copied from another company, a software platform may enable optional fields by default, or a team may retain information because it could possibly be useful later.

This creates more information to manage and protect. It can also make it harder to explain why the business has collected it.

A practical first action is to review the forms and processes used most often, including:

  • Website contact and enquiry forms.
  • Customer onboarding questionnaires.
  • Newsletter and event registrations.
  • Employee and contractor onboarding.
  • Recruitment applications.
  • Support and service requests.

For each field, consider what the information will be used for and whether that purpose could be achieved with less information. Particular care may be appropriate when collecting financial, health, identity, biometric or other sensitive information.

Consent may be required in some situations, but it is not the only basis on which personal information can be handled under every privacy law. The appropriate approach depends on the jurisdiction, the information and the reason it is being used.

Be open about how information is handled

Transparency is one of the clearest themes across privacy regulation.

People should be able to understand what information a business collects, why it is collected, how it will be used, who it may be shared with and how they can raise a privacy question. The UK GDPR places lawfulness, fairness and transparency at the centre of its principles. Australian law requires open and transparent management of personal information, while California law gives consumers rights to know about the information covered businesses collect and how it is used or shared.

For most businesses, the privacy policy is the main place where this is explained. Other notices may also appear beside website forms, account registrations, job applications or marketing sign-ups.

What commonly goes wrong is a gap between the written policy and the way the business actually operates. A generic policy may refer to information the business never collects, omit important software providers or describe choices that people cannot easily exercise.

A sensible first action is to compare the privacy policy with the personal information inventory. Check whether it accurately describes:

  • The categories of information collected.
  • The purposes for which information is used.
  • The main types of providers or other parties receiving it.
  • Any important international handling of the information.
  • The choices and rights available to individuals.
  • How someone can contact the business about privacy.

A shorter policy that reflects reality is more useful than a detailed document that nobody inside the business can confidently explain.

Use information consistently with the reason it was collected

Once personal information has been collected, businesses should remain aware of the purpose for which it was obtained.

This becomes important when a team finds a new use for existing information. Customer records might be added to a marketing campaign, support conversations might be analysed using a new artificial intelligence service, or information collected for account administration might be combined with data from another platform.

These new uses are not automatically inappropriate. They do, however, deserve a deliberate review.

The business should consider whether the new activity is compatible with the original purpose, whether people were told about it, and whether an additional notice, consent or other legal basis may be required. Purpose specification and use limitation are both part of the OECD privacy principles, while the GDPR and UK GDPR include purpose limitation among their core requirements.

A practical first step is to include a short privacy check whenever the business introduces a new system, integration, analytics process or use of customer or employee information. That small pause can identify issues while they are still easy to address.

Share information carefully with service providers

Most businesses depend on external providers to operate. These may include cloud hosting companies, accountants, payroll services, marketing platforms, IT providers, customer support tools and software vendors.

Using reputable providers can strengthen a business, but it does not remove the need to understand where personal information is going and how it will be handled.

A common difficulty is that providers are added one at a time. Several years later, the business may have no central record of which services hold personal information, what contracts apply or whether former providers still retain copies.

A basic provider register can bring this into view. For each important provider, record:

  • The service being provided.
  • The categories of personal information involved.
  • The reason the provider receives the information.
  • Where the information is likely to be stored.
  • Whether other subcontractors may be involved.
  • What the contract says about security, privacy, deletion and incidents.
  • Who inside the business manages the relationship.

International transfers and disclosures are an area where the detailed rules differ considerably between countries. A business may need to examine where information is stored, which legal entities receive it and what contractual protections are in place.

The shared foundation is straightforward: know which providers handle personal information and make considered decisions about using them.

Keep personal information accurate

Incorrect information can affect customer service, employee administration, financial decisions and the way people are treated.

Accuracy is a core principle under the GDPR and UK GDPR. Australian privacy principles address the quality and correction of personal information, while New Zealand law gives individuals rights to request access to and correction of their information.

Accuracy problems often arise when the same information is stored in several systems. Someone may update their address in one platform while an older version remains in a spreadsheet, email list or accounting system.

A sensible first action is to identify which system should be treated as the main record for important customer and employee information. The business can then decide how corrections are passed to other systems and providers.

It also helps to give people a straightforward way to report inaccurate information. The process does not need to be elaborate, but someone should know who receives the request and how the correction will be followed through.

Protect information with reasonable security safeguards

Privacy and cybersecurity overlap most clearly when personal information is stored, accessed and shared.

The OECD principles call for reasonable security safeguards. Australian privacy law requires covered organisations to take reasonable steps to protect personal information, and New Zealand’s fifth privacy principle requires safeguards that are reasonable in the circumstances. The GDPR and UK GDPR include integrity and confidentiality within their core data protection principles.

What counts as reasonable will depend on the business and the information involved. A company holding health records, identity documents or large volumes of financial information will usually require stronger safeguards than one holding basic contact details for a small mailing list.

For many small and growing businesses, a sound starting point includes:

  • Multi-factor authentication on important accounts.
  • Access based on each person’s role.
  • Prompt removal of access when someone leaves.
  • Secure, updated and encrypted work devices.
  • Regular reviews of shared folders and external links.
  • Reliable backups that are protected and tested.
  • Clear security expectations for external providers.
  • A simple way for employees to report mistakes and suspicious activity.

Security measures work best when they reflect how the business actually operates. A complicated control that is regularly bypassed may offer less protection than a simpler process that people can follow consistently.

Keep information only while there is a reason to retain it

Personal information tends to accumulate because keeping it is easier than deciding what should be deleted.

Old customer exports, unsuccessful job applications, former employee documents, outdated mailing lists and abandoned accounts can remain in systems long after their original purpose has passed. This increases the volume of information that must be secured, searched and managed.

Storage limitation is a core principle under the GDPR and UK GDPR. Other privacy frameworks also address retention and the disposal or de-identification of information that is no longer required.

A common mistake is looking for one retention period that can be applied to everything. Different records may be affected by tax, employment, contractual, insurance or industry requirements.

A more useful approach is to select the main categories of information and decide:

  • Why the information is being retained.
  • Whether a legal or contractual requirement applies.
  • How long it is normally useful.
  • Who approves deletion.
  • How it will be removed from active systems and routine exports.
  • Whether providers and backups require separate consideration.

The first version of a retention schedule can be simple. Its value comes from turning indefinite storage into a conscious business decision.

Give people a practical way to exercise their rights

The precise rights available to an individual depend on the law that applies.

Access and correction are common across many frameworks. Other laws may provide rights involving deletion, portability, objection, restriction, opting out of sale or sharing, or limiting the use of sensitive information. California’s CCPA, for example, gives consumers rights to know, delete, correct and opt out of certain uses of personal information.

The practical foundation is having a repeatable process for receiving and managing requests.

That process should make clear:

  • Where a person can submit a request.
  • Who inside the business is responsible for it.
  • How the person’s identity will be verified.
  • Which systems and providers may need to be searched.
  • How the response and any decisions will be documented.
  • When legal or specialist advice may be appropriate.

Deadlines and permitted exceptions vary between jurisdictions. Businesses should confirm the relevant requirements rather than adopting one response period for every request.

Even so, having a named owner and a basic process makes it much easier to respond calmly and consistently.

Be prepared for a privacy incident

A privacy incident can involve malicious activity, but many incidents begin with an ordinary mistake.

An email may be sent to the wrong person, a shared folder may be left open, a laptop may be lost or an employee account may be compromised. What matters next is whether the business can understand the situation and make informed decisions.

A practical response process usually covers:

  1. Containing the incident and preventing further exposure.
  2. Establishing what information may be involved.
  3. Identifying the people who may be affected.
  4. Recording what happened and what actions were taken.
  5. Assessing the likely consequences.
  6. Determining whether anyone must be notified.
  7. Addressing the cause and improving the relevant safeguards.

Breach notification tests, reporting deadlines and regulator expectations differ between countries. A shared response process will not answer every legal question, but it gives the business the information needed to work through them.

The first action is to identify who should be contacted when a possible privacy incident is discovered. Employees should not have to work out the reporting path while an incident is unfolding.

Make someone responsible for keeping privacy work moving

Privacy activities can easily become spread across business owners, marketing teams, human resources, IT providers and software vendors.

Each person may manage their own part responsibly, while nobody has a complete view of how personal information moves through the business. Reviews are then delayed, requests are handled differently and outdated processes remain in place.

Accountability is one of the OECD privacy principles and one of the core GDPR and UK GDPR principles. Australian privacy law also includes governance and accountability obligations within the Australian Privacy Principles.

A small business may not require a full-time privacy specialist. It still helps to name someone who coordinates the work and makes sure responsibilities are clear.

That person might oversee:

  • The personal information inventory.
  • Privacy policies and notices.
  • Reviews of important providers.
  • Individual privacy requests.
  • Retention and deletion decisions.
  • Privacy incident procedures.
  • Reviews when systems or business activities change.

They do not have to perform every task themselves. Their role is to make sure each task has an owner and reaches a sensible conclusion.

The details still depend on the law that applies

A strong foundation can support compliance across several countries, but privacy laws are not interchangeable.

Important differences may include:

  • Which businesses and activities are covered.
  • Whether a law applies to businesses located outside the country.
  • How personal and sensitive information are defined.
  • The permitted reasons for handling information.
  • When consent is required.
  • How employee and children’s information is treated.
  • Rules for cookies, tracking and electronic marketing.
  • Requirements for international transfers.
  • The rights available to individuals.
  • Deadlines for responding to requests.
  • Breach notification tests and timeframes.
  • Requirements for privacy officers, representatives or data protection officers.
  • Record-keeping and impact assessment obligations.
  • Enforcement powers and penalties.

These differences are why a general privacy program should be followed by a jurisdiction-specific review.

The common principles make that review more manageable. Instead of starting from an empty page for every country, the business can examine an existing set of information, policies and processes, then identify where additional work is required.

A practical privacy foundation

For a business starting this work, five actions provide a useful foundation:

  1. Create a simple inventory of the personal information the business holds.
  2. Review what is being collected and why it is needed.
  3. Compare the privacy policy with actual business practices.
  4. Identify the systems and providers that handle personal information.
  5. Assign responsibility for requests, retention and privacy incidents.

These actions support several privacy obligations at the same time. They also give the business a clearer basis for speaking with legal advisers, customers, insurers and technology providers.

Privacy compliance develops over time as systems, providers and business activities change. A clear view of the information being handled makes those changes easier to assess and helps the business make more confident decisions.

How BrightShield can help

BrightShield helps small and growing businesses turn broad privacy expectations into a clear and practical improvement plan.

This can include:

  • Identifying personal information across business systems and providers.
  • Helping determine which privacy frameworks require closer review.
  • Comparing privacy policies with actual business practices.
  • Reviewing how information is collected, accessed, shared, retained and deleted.
  • Assessing the cybersecurity safeguards protecting personal information.
  • Preparing practical processes for privacy requests and incidents.
  • Creating a prioritised Cyber Action Plan.
  • Supporting implementation through Guided or managing the work through Complete.

BrightShield focuses on the practical, operational and cybersecurity work that supports privacy compliance. Where formal legal interpretation is needed, we can help the business organise the relevant information and work effectively with its legal adviser.

The privacy laws applying to a business may come from several places, but the first steps remain reassuringly familiar. Understand the information you hold, make deliberate decisions about how it is used, protect it appropriately and give people a clear way to ask questions about it. From there, the detailed requirements become much easier to approach.

Subscribe to our newsletter

Every week we publish a short email on a topic we think you'll find interesting. We know you're busy, so we keep it short, snappy, and relevant.

Let's Begin

Ready to understand your security risks?

Get a clear, practical view of your risks and a plan to fix them with a BrightShield Security Audit.