Blog

5 Regional E-Commerce Privacy Laws Compared

By
The Reform Team
Use AI to summarize text or ask questions

Where your shopper lives usually matters more than where your store is based. If you sell across borders, five privacy systems shape most day-to-day decisions: GDPR, CCPA/CPRA, LGPD, PIPEDA, and major APAC country rules.

Here’s the short version:

  • GDPR is the toughest starting point for many stores, with opt-in rules for non-necessary cookies and marketing.
  • CCPA/CPRA uses an opt-out model for sale and sharing, plus Global Privacy Control (GPC) support.
  • LGPD looks close to GDPR, with legal bases, user rights, and transfer rules.
  • PIPEDA leans on meaningful consent, with fewer consumer rights than GDPR.
  • APAC is not one law. Stores need to check each market, especially South Korea, Japan, Singapore, Australia, and India.

This comparison looks at six points that affect e-commerce work fast:

  • Scope
  • Consent
  • Shopper rights
  • Cookie rules
  • Cross-border transfers
  • Form notices

A few facts stand out. Brazil received EU adequacy status in January 2026. India’s DPDPA is law, but full enforcement starts on May 13, 2027. And Quebec now uses an opt-in cookie default, which sets it apart in North America.

Quick Comparison

Framework Who it covers Consent model Shopper rights Cookie rule Transfer rule Form notice
GDPR Stores targeting EU/UK residents Opt-in for non-necessary processing Access, deletion, correction, portability, objection Prior consent Adequacy or SCCs Notice at collection
CCPA/CPRA California residents if thresholds are met Opt-out for sale/sharing Access, deletion, correction, opt-out Opt-out with GPC No set cross-border rule like GDPR Categories and purpose at collection
LGPD Stores targeting Brazil residents Opt-in in many marketing/cookie cases Access, deletion, correction, portability Prior consent Adequacy or SCCs Legal basis and purpose
PIPEDA Commercial activity in Canada Meaningful consent; implied consent can apply Access and correction Notice and opt-out in many cases Comparable protection Purpose at collection
APAC rules Country by country Mixed Mixed Mixed Mixed Mixed

If I had to reduce the whole article to one takeaway, it’s this: use geo-based privacy settings, separate marketing consent from checkout, and map every vendor that receives customer data.

5 regional frameworks compared: GDPR, CCPA/CPRA, LGPD, PIPEDA, and APAC rules

GDPR: The strict opt-in baseline for global online stores

GDPR applies to any online store that targets people in the EU or UK, no matter where the store is located. That reach is why many e-commerce teams use GDPR as the baseline for privacy compliance across markets.

For any nonessential processing, a store needs a lawful basis. That can be consent, legitimate interest, contract, or another recognized ground. For cookies and marketing, consent has to come from a clear affirmative action. Pre-ticked boxes don't qualify.

Shoppers also get a strong set of rights. Those include access, deletion, correction, portability, and the right to object to profiling. Cross-border transfers need adequacy decisions or standard contractual clauses, and forms need a notice at collection.

That comparison changes fast in California, where the model leans on opt-out rights instead of GDPR-style consent.


CCPA/CPRA: California's opt-out model for sale, sharing, and tracking disclosures

CCPA/CPRA applies to California residents once a business meets revenue or data-volume thresholds. Instead of broad opt-in rules, it gives shoppers the right to opt out of the sale or sharing of their personal information.

Businesses must post a "Do Not Sell or Share My Personal Information" link and honor Global Privacy Control (GPC) signals. Shopper rights include access, deletion, correction, and the right to opt out of sale or sharing. For users under 16, opt-in consent is required.

Cookie rules also follow an opt-out approach tied to the GPC signal. Unlike GDPR, California does not impose specific limits on cross-border transfers. Lead-gen and checkout forms must disclose the categories of data collected and the purpose at collection. Stores that use automated pricing or credit decisions may also need added disclosures under California's ADMT requirements.

Brazil looks close to GDPR on paper, but the day-to-day details differ.


LGPD: Brazil's GDPR-like framework with local enforcement differences

LGPD applies worldwide to any store that targets Brazilian residents. Its structure is close to GDPR: it has 10 legal bases for processing, broad reach beyond Brazil, and opt-in consent for marketing and cookies.

Shoppers have rights to access, deletion, portability, and correction. International transfers depend on adequacy mechanisms or standard contractual clauses. Forms also need to state the legal basis for processing.

The main difference from GDPR is less about the written rules and more about local enforcement and transfer mechanics.

Canada takes another route, with a focus on meaningful consent instead of GDPR-style lawful bases.


PIPEDA covers private-sector organizations that collect, use, or disclose personal information during commercial activity in Canada. Its core idea is meaningful consent, paired with fair information principles.

For sensitive data, such as health or financial information, express opt-in consent is required. For less sensitive data, implied consent may be enough. The same can apply to non-sensitive tracking.

Shopper rights are narrower than under GDPR. People can request access and correction, but not deletion or portability. Cross-border transfers must provide comparable protection. Forms need a clear statement of purpose at the point of collection.

APAC works very differently. It isn't one system. It's a patchwork of country-specific laws.


APAC market rules: Australia, Singapore, Japan, South Korea, and India

No single APAC law covers the whole region. Each country sets its own rules, and the differences are big enough that stores need to review each market on its own.

Here's the short version:

Market Main rule Consent model Transfer rule Form requirement
Australia Privacy Act 1988 Generally implied for non-sensitive data Comparable protection required Clear collection notice under the Australian Privacy Principles
Singapore Personal Data Protection Act (PDPA) Opt-out model for most processing; deemed consent often applies Permitted with adequate protection Purpose of collection must be stated
Japan Act on the Protection of Personal Information (APPI) Opt-in for sensitive data and third-party transfers Consent or comparable protection for third-party cross-border transfers Notice at collection and purpose limitation
South Korea Personal Information Protection Act (PIPA) Opt-in for collection and use Explicit consent required Detailed notice covering purpose, items collected, and retention period
India Digital Personal Data Protection Act (DPDPA) Consent-based Permitted to approved countries Collection notices and documented consent records once enforcement begins

A few market-specific points matter here.

Australia applies its Privacy Act 1988 to businesses with annual turnover above AUD $3 million. Consent is generally implied for non-sensitive data, and cross-border transfers need comparable protection. Forms must include a clear collection notice under the Australian Privacy Principles.

Singapore's PDPA uses an opt-out model for most processing. Consent is required for collection, use, and disclosure, but deemed consent shows up often in commercial settings. Cross-border transfers are allowed if adequate protection is in place. Forms must state why the data is being collected.

Japan's APPI requires opt-in consent for sensitive data and third-party transfers. For standard data, the main duties are purpose limitation and notice at collection. Cross-border transfers to third parties need either consent or a comparable protection standard.

South Korea's PIPA is one of the stricter frameworks in the region. It requires opt-in consent for collection and use, mandatory disclosure of retention periods, and explicit consent for cross-border transfers. Shopper rights include access, deletion, and correction. Forms must include detailed collection notices covering purpose, items collected, and retention period.

India's Digital Personal Data Protection Act (DPDPA) has been enacted but is not yet fully enforced. It requires consent for processing personal data, gives people rights of access, correction, and erasure, and calls for a consent manager mechanism in some contexts. Cross-border transfers are allowed to approved countries. Once enforcement starts, stores targeting Indian residents will need collection notices and documented consent records.

Rules vary a lot from market to market. Some lean on opt-in. Others allow opt-out.

Master comparison matrix for e-commerce teams

5 E-Commerce Privacy Laws Compared: GDPR, CCPA, LGPD, PIPEDA & APAC

5 E-Commerce Privacy Laws Compared: GDPR, CCPA, LGPD, PIPEDA & APAC

Use this matrix to turn the earlier rules into day-to-day choices around checkout, tracking, and vendors. It shows which rules most often change forms, cookies, and vendor handoffs.

Dimension GDPR (EU) CCPA/CPRA (California) LGPD (Brazil) PIPEDA (Canada) APAC (Major Markets)
Scope Any store targeting EU residents California-specific thresholds Any store targeting Brazilian residents Private-sector commercial activity in Canada Country-specific, often extraterritorial
Consent model Strict opt-in for non-essential processing Opt-out for sale/sharing Opt-in, GDPR-like Meaningful consent; implied consent for low-risk uses Varies by country; opt-in is common, Singapore leans opt-out, India relies on affirmative consent
Shopper rights Access, deletion, correction, portability, right to object Access, deletion, correction, opt-out of sale/sharing Access, deletion, portability, correction Access and correction Access and correction are common; portability is expanding
Cookie rules Prior consent required for non-essential cookies Opt-out via "Do Not Sell or Share My Personal Information" link and GPC signal Prior consent required Transparency and opt-out Opt-in in stricter markets; notice-based in Australia
Data transfer limits Adequacy decisions or SCCs required No federal transfer limit GDPR-style limits Comparable protection required Security or comparable-protection checks are required in several markets
Form data duties Notice at collection with clear purpose Notice at collection listing categories and purpose Clear notice at collection Clear purpose statement at collection Notice requirements vary by country; India requires multilingual notices

Brazil also received EU adequacy status in January 2026. That makes data flows simpler between LGPD-covered stores and EU-based vendors or CRM platforms.

Which framework affects stores the most day to day

Out of these five, GDPR and South Korea's PIPA usually create the most day-to-day work.

GDPR requires opt-in for non-essential processing, stops non-essential scripts until consent is given, and depends on vendor agreements plus transfer safeguards. South Korea's PIPA goes a step further. It requires separate consent for each distinct purpose of processing, which makes it the most granular rule set in the APAC region.

The table below translates those legal differences into common store actions.

Store activity GDPR CCPA/CPRA LGPD PIPEDA APAC highlights
Checkout forms Notice at collection with clear purpose Notice at collection listing categories and purpose Clear notice at collection Clear purpose statement South Korea requires separate consent by purpose; India requires multilingual notices
Newsletter signups Opt-in; no pre-ticked boxes Opt-out model for standard commercial emails Opt-in required Meaningful consent; implied consent can apply for low-risk activity South Korea and India require affirmative consent; India does not rely on a broad legitimate interests basis
Remarketing cookies Block until user opts in Provide the "Do Not Sell or Share My Personal Information" link and honor GPC Block until user opts in Transparency and opt-out China, South Korea, Thailand, and Vietnam require opt-in before non-essential cookies are set
Vendor transfers Adequacy decisions or SCCs; data processing agreements required No federal transfer limit Adequacy decisions or SCCs; data processing agreements required Comparable protection required China and Vietnam require security assessments; Australia's APP 8 makes the disclosing entity liable for breaches by an overseas recipient

What online stores should change in forms, tracking, and data flows

Break this review into three checks: forms, tags, and vendors.

Every form on your store - checkout, newsletter signup, account registration, and other lead forms - needs a plain-language notice right where the data is collected. That notice should say what data you’re collecting and exactly why. Keep marketing consent separate from checkout, tie each field to a documented purpose, and set up retention and deletion workflows in your CRM.

Once form data lands in your CRM, inactive records should be deleted on a set schedule to meet storage limitation rules. If you serve Brazilian shoppers, access and deletion requests need automated workflows across your CRM, email platform, and analytics tools. A form builder like Reform can help you collect only the fields you need and keep consent records in order.

Cookies, remarketing tags, and cross-border vendors

After forms, review every script that loads before and after consent.

Strictly necessary tags - cart session tokens, authentication cookies, and fraud detection tools - can load without prior consent. Nonessential tags - analytics, ad pixels, and product recommendation engines - need opt-in before loading in GDPR, LGPD, and Quebec Law 25 jurisdictions.

Geo-targeted consent rules matter here:

  • EU/UK/Quebec/Brazil: strict opt-in
  • California: opt-out disclosures
  • Google Ads or GA4 in the EEA: Google Consent Mode v2 to keep conversion modeling working when users decline

Then follow the data. Where does each vendor receive it, and where does it go after that? If a vendor processes data abroad, document the transfer mechanism and review every app, plugin, and tool in your stack. Australia’s APP 8 makes the disclosing entity liable for breaches by overseas recipients, and Japan’s APPI requires clear disclosures before data leaves the country.

Conclusion: Key takeaways from the 5 privacy frameworks

The matrix makes one point plain: GDPR sets the toughest baseline. CCPA/CPRA follows an opt-out model. LGPD looks a lot like GDPR. PIPEDA relies on consent. And across APAC, privacy rules are still a country-by-country patchwork.

Those differences shouldn't sit on a chart and go nowhere. They need to shape how you collect consent and where you send data. In practice, that means lining up your conversion-optimized forms, consent notices, cookie behavior, and vendor contracts with where your shoppers are based.

A geo-targeted consent setup does exactly that. Use opt-in banners for visitors from the EU, UK, and Brazil, and opt-out notices for people in California. That lines up with the biggest regional gaps.

Privacy rules don't sit still, either. So audit your privacy stack at least once a year. Laws in this area change fast.

FAQs

Which privacy law applies to my store first?

It comes down to where your customers live, not where your store is based. Laws such as GDPR, CCPA/CPRA, and India’s DPDPA may apply if you offer goods or services to people in those places or track their online behavior.

If you sell to customers across more than one region, you may need to follow more than one law at the same time. Review each law on its own so you can see exactly what it requires.

Yes. Rules change a lot from one region to another, so it’s normal to show different cookie banner settings based on where a visitor is located.

The EU, UK, and Brazil usually require opt-in consent before non-essential cookies can load. In most U.S. states, the model is opt-out instead. And in some places, clear disclosure is enough.

What should I audit in my forms and vendors?

Regularly audit your forms, vendor contracts, and security practices.

Your forms should be clear, easy to understand, and limited to the data you actually need. They should also support key privacy rights, including access, deletion, and opt-out requests. Keep time-stamped consent logs too, including any withdrawals and the exact banner version a person saw at the time.

For vendors, check that contracts limit data use to the services you spelled out. They should also ban the sale or sharing of personal information and give you the right to audit compliance. On the security side, review core safeguards like encryption, multi-factor authentication, and incident response processes.

Related Blog Posts

Use AI to summarize text or ask questions

Discover proven form optimizations that drive real results for B2B, Lead/Demand Generation, and SaaS companies.

Lead Conversion Playbook

Get new content delivered straight to your inbox

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
The Playbook

Drive real results with form optimizations

Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.