5 Regional E-Commerce Privacy Laws Compared

Where your shopper lives usually matters more than where your store is based. If you sell across borders, five privacy systems shape most day-to-day decisions: GDPR, CCPA/CPRA, LGPD, PIPEDA, and major APAC country rules.
Here’s the short version:
- GDPR is the toughest starting point for many stores, with opt-in rules for non-necessary cookies and marketing.
- CCPA/CPRA uses an opt-out model for sale and sharing, plus Global Privacy Control (GPC) support.
- LGPD looks close to GDPR, with legal bases, user rights, and transfer rules.
- PIPEDA leans on meaningful consent, with fewer consumer rights than GDPR.
- APAC is not one law. Stores need to check each market, especially South Korea, Japan, Singapore, Australia, and India.
This comparison looks at six points that affect e-commerce work fast:
- Scope
- Consent
- Shopper rights
- Cookie rules
- Cross-border transfers
- Form notices
A few facts stand out. Brazil received EU adequacy status in January 2026. India’s DPDPA is law, but full enforcement starts on May 13, 2027. And Quebec now uses an opt-in cookie default, which sets it apart in North America.
Quick Comparison
| Framework | Who it covers | Consent model | Shopper rights | Cookie rule | Transfer rule | Form notice |
|---|---|---|---|---|---|---|
| GDPR | Stores targeting EU/UK residents | Opt-in for non-necessary processing | Access, deletion, correction, portability, objection | Prior consent | Adequacy or SCCs | Notice at collection |
| CCPA/CPRA | California residents if thresholds are met | Opt-out for sale/sharing | Access, deletion, correction, opt-out | Opt-out with GPC | No set cross-border rule like GDPR | Categories and purpose at collection |
| LGPD | Stores targeting Brazil residents | Opt-in in many marketing/cookie cases | Access, deletion, correction, portability | Prior consent | Adequacy or SCCs | Legal basis and purpose |
| PIPEDA | Commercial activity in Canada | Meaningful consent; implied consent can apply | Access and correction | Notice and opt-out in many cases | Comparable protection | Purpose at collection |
| APAC rules | Country by country | Mixed | Mixed | Mixed | Mixed | Mixed |
If I had to reduce the whole article to one takeaway, it’s this: use geo-based privacy settings, separate marketing consent from checkout, and map every vendor that receives customer data.
sbb-itb-5f36581
5 regional frameworks compared: GDPR, CCPA/CPRA, LGPD, PIPEDA, and APAC rules
GDPR: The strict opt-in baseline for global online stores
GDPR applies to any online store that targets people in the EU or UK, no matter where the store is located. That reach is why many e-commerce teams use GDPR as the baseline for privacy compliance across markets.
For any nonessential processing, a store needs a lawful basis. That can be consent, legitimate interest, contract, or another recognized ground. For cookies and marketing, consent has to come from a clear affirmative action. Pre-ticked boxes don't qualify.
Shoppers also get a strong set of rights. Those include access, deletion, correction, portability, and the right to object to profiling. Cross-border transfers need adequacy decisions or standard contractual clauses, and forms need a notice at collection.
That comparison changes fast in California, where the model leans on opt-out rights instead of GDPR-style consent.
CCPA/CPRA: California's opt-out model for sale, sharing, and tracking disclosures
CCPA/CPRA applies to California residents once a business meets revenue or data-volume thresholds. Instead of broad opt-in rules, it gives shoppers the right to opt out of the sale or sharing of their personal information.
Businesses must post a "Do Not Sell or Share My Personal Information" link and honor Global Privacy Control (GPC) signals. Shopper rights include access, deletion, correction, and the right to opt out of sale or sharing. For users under 16, opt-in consent is required.
Cookie rules also follow an opt-out approach tied to the GPC signal. Unlike GDPR, California does not impose specific limits on cross-border transfers. Lead-gen and checkout forms must disclose the categories of data collected and the purpose at collection. Stores that use automated pricing or credit decisions may also need added disclosures under California's ADMT requirements.
Brazil looks close to GDPR on paper, but the day-to-day details differ.
LGPD: Brazil's GDPR-like framework with local enforcement differences
LGPD applies worldwide to any store that targets Brazilian residents. Its structure is close to GDPR: it has 10 legal bases for processing, broad reach beyond Brazil, and opt-in consent for marketing and cookies.
Shoppers have rights to access, deletion, portability, and correction. International transfers depend on adequacy mechanisms or standard contractual clauses. Forms also need to state the legal basis for processing.
The main difference from GDPR is less about the written rules and more about local enforcement and transfer mechanics.
Canada takes another route, with a focus on meaningful consent instead of GDPR-style lawful bases.
PIPEDA: Canada's meaningful consent standard for commercial activity
PIPEDA covers private-sector organizations that collect, use, or disclose personal information during commercial activity in Canada. Its core idea is meaningful consent, paired with fair information principles.
For sensitive data, such as health or financial information, express opt-in consent is required. For less sensitive data, implied consent may be enough. The same can apply to non-sensitive tracking.
Shopper rights are narrower than under GDPR. People can request access and correction, but not deletion or portability. Cross-border transfers must provide comparable protection. Forms need a clear statement of purpose at the point of collection.
APAC works very differently. It isn't one system. It's a patchwork of country-specific laws.
APAC market rules: Australia, Singapore, Japan, South Korea, and India
No single APAC law covers the whole region. Each country sets its own rules, and the differences are big enough that stores need to review each market on its own.
Here's the short version:
| Market | Main rule | Consent model | Transfer rule | Form requirement |
|---|---|---|---|---|
| Australia | Privacy Act 1988 | Generally implied for non-sensitive data | Comparable protection required | Clear collection notice under the Australian Privacy Principles |
| Singapore | Personal Data Protection Act (PDPA) | Opt-out model for most processing; deemed consent often applies | Permitted with adequate protection | Purpose of collection must be stated |
| Japan | Act on the Protection of Personal Information (APPI) | Opt-in for sensitive data and third-party transfers | Consent or comparable protection for third-party cross-border transfers | Notice at collection and purpose limitation |
| South Korea | Personal Information Protection Act (PIPA) | Opt-in for collection and use | Explicit consent required | Detailed notice covering purpose, items collected, and retention period |
| India | Digital Personal Data Protection Act (DPDPA) | Consent-based | Permitted to approved countries | Collection notices and documented consent records once enforcement begins |
A few market-specific points matter here.
Australia applies its Privacy Act 1988 to businesses with annual turnover above AUD $3 million. Consent is generally implied for non-sensitive data, and cross-border transfers need comparable protection. Forms must include a clear collection notice under the Australian Privacy Principles.
Singapore's PDPA uses an opt-out model for most processing. Consent is required for collection, use, and disclosure, but deemed consent shows up often in commercial settings. Cross-border transfers are allowed if adequate protection is in place. Forms must state why the data is being collected.
Japan's APPI requires opt-in consent for sensitive data and third-party transfers. For standard data, the main duties are purpose limitation and notice at collection. Cross-border transfers to third parties need either consent or a comparable protection standard.
South Korea's PIPA is one of the stricter frameworks in the region. It requires opt-in consent for collection and use, mandatory disclosure of retention periods, and explicit consent for cross-border transfers. Shopper rights include access, deletion, and correction. Forms must include detailed collection notices covering purpose, items collected, and retention period.
India's Digital Personal Data Protection Act (DPDPA) has been enacted but is not yet fully enforced. It requires consent for processing personal data, gives people rights of access, correction, and erasure, and calls for a consent manager mechanism in some contexts. Cross-border transfers are allowed to approved countries. Once enforcement starts, stores targeting Indian residents will need collection notices and documented consent records.
Rules vary a lot from market to market. Some lean on opt-in. Others allow opt-out.
Master comparison matrix for e-commerce teams
5 E-Commerce Privacy Laws Compared: GDPR, CCPA, LGPD, PIPEDA & APAC
Use this matrix to turn the earlier rules into day-to-day choices around checkout, tracking, and vendors. It shows which rules most often change forms, cookies, and vendor handoffs.
| Dimension | GDPR (EU) | CCPA/CPRA (California) | LGPD (Brazil) | PIPEDA (Canada) | APAC (Major Markets) |
|---|---|---|---|---|---|
| Scope | Any store targeting EU residents | California-specific thresholds | Any store targeting Brazilian residents | Private-sector commercial activity in Canada | Country-specific, often extraterritorial |
| Consent model | Strict opt-in for non-essential processing | Opt-out for sale/sharing | Opt-in, GDPR-like | Meaningful consent; implied consent for low-risk uses | Varies by country; opt-in is common, Singapore leans opt-out, India relies on affirmative consent |
| Shopper rights | Access, deletion, correction, portability, right to object | Access, deletion, correction, opt-out of sale/sharing | Access, deletion, portability, correction | Access and correction | Access and correction are common; portability is expanding |
| Cookie rules | Prior consent required for non-essential cookies | Opt-out via "Do Not Sell or Share My Personal Information" link and GPC signal | Prior consent required | Transparency and opt-out | Opt-in in stricter markets; notice-based in Australia |
| Data transfer limits | Adequacy decisions or SCCs required | No federal transfer limit | GDPR-style limits | Comparable protection required | Security or comparable-protection checks are required in several markets |
| Form data duties | Notice at collection with clear purpose | Notice at collection listing categories and purpose | Clear notice at collection | Clear purpose statement at collection | Notice requirements vary by country; India requires multilingual notices |
Brazil also received EU adequacy status in January 2026. That makes data flows simpler between LGPD-covered stores and EU-based vendors or CRM platforms.
Which framework affects stores the most day to day
Out of these five, GDPR and South Korea's PIPA usually create the most day-to-day work.
GDPR requires opt-in for non-essential processing, stops non-essential scripts until consent is given, and depends on vendor agreements plus transfer safeguards. South Korea's PIPA goes a step further. It requires separate consent for each distinct purpose of processing, which makes it the most granular rule set in the APAC region.
The table below translates those legal differences into common store actions.
| Store activity | GDPR | CCPA/CPRA | LGPD | PIPEDA | APAC highlights |
|---|---|---|---|---|---|
| Checkout forms | Notice at collection with clear purpose | Notice at collection listing categories and purpose | Clear notice at collection | Clear purpose statement | South Korea requires separate consent by purpose; India requires multilingual notices |
| Newsletter signups | Opt-in; no pre-ticked boxes | Opt-out model for standard commercial emails | Opt-in required | Meaningful consent; implied consent can apply for low-risk activity | South Korea and India require affirmative consent; India does not rely on a broad legitimate interests basis |
| Remarketing cookies | Block until user opts in | Provide the "Do Not Sell or Share My Personal Information" link and honor GPC | Block until user opts in | Transparency and opt-out | China, South Korea, Thailand, and Vietnam require opt-in before non-essential cookies are set |
| Vendor transfers | Adequacy decisions or SCCs; data processing agreements required | No federal transfer limit | Adequacy decisions or SCCs; data processing agreements required | Comparable protection required | China and Vietnam require security assessments; Australia's APP 8 makes the disclosing entity liable for breaches by an overseas recipient |
What online stores should change in forms, tracking, and data flows
Form collection notices, consent records, and CRM handoffs
Break this review into three checks: forms, tags, and vendors.
Every form on your store - checkout, newsletter signup, account registration, and other lead forms - needs a plain-language notice right where the data is collected. That notice should say what data you’re collecting and exactly why. Keep marketing consent separate from checkout, tie each field to a documented purpose, and set up retention and deletion workflows in your CRM.
Once form data lands in your CRM, inactive records should be deleted on a set schedule to meet storage limitation rules. If you serve Brazilian shoppers, access and deletion requests need automated workflows across your CRM, email platform, and analytics tools. A form builder like Reform can help you collect only the fields you need and keep consent records in order.
Cookies, remarketing tags, and cross-border vendors
After forms, review every script that loads before and after consent.
Strictly necessary tags - cart session tokens, authentication cookies, and fraud detection tools - can load without prior consent. Nonessential tags - analytics, ad pixels, and product recommendation engines - need opt-in before loading in GDPR, LGPD, and Quebec Law 25 jurisdictions.
Geo-targeted consent rules matter here:
- EU/UK/Quebec/Brazil: strict opt-in
- California: opt-out disclosures
- Google Ads or GA4 in the EEA: Google Consent Mode v2 to keep conversion modeling working when users decline
Then follow the data. Where does each vendor receive it, and where does it go after that? If a vendor processes data abroad, document the transfer mechanism and review every app, plugin, and tool in your stack. Australia’s APP 8 makes the disclosing entity liable for breaches by overseas recipients, and Japan’s APPI requires clear disclosures before data leaves the country.
Conclusion: Key takeaways from the 5 privacy frameworks
The matrix makes one point plain: GDPR sets the toughest baseline. CCPA/CPRA follows an opt-out model. LGPD looks a lot like GDPR. PIPEDA relies on consent. And across APAC, privacy rules are still a country-by-country patchwork.
Those differences shouldn't sit on a chart and go nowhere. They need to shape how you collect consent and where you send data. In practice, that means lining up your conversion-optimized forms, consent notices, cookie behavior, and vendor contracts with where your shoppers are based.
A geo-targeted consent setup does exactly that. Use opt-in banners for visitors from the EU, UK, and Brazil, and opt-out notices for people in California. That lines up with the biggest regional gaps.
Privacy rules don't sit still, either. So audit your privacy stack at least once a year. Laws in this area change fast.
FAQs
Which privacy law applies to my store first?
It comes down to where your customers live, not where your store is based. Laws such as GDPR, CCPA/CPRA, and India’s DPDPA may apply if you offer goods or services to people in those places or track their online behavior.
If you sell to customers across more than one region, you may need to follow more than one law at the same time. Review each law on its own so you can see exactly what it requires.
Do I need different cookie banners by region?
Yes. Rules change a lot from one region to another, so it’s normal to show different cookie banner settings based on where a visitor is located.
The EU, UK, and Brazil usually require opt-in consent before non-essential cookies can load. In most U.S. states, the model is opt-out instead. And in some places, clear disclosure is enough.
What should I audit in my forms and vendors?
Regularly audit your forms, vendor contracts, and security practices.
Your forms should be clear, easy to understand, and limited to the data you actually need. They should also support key privacy rights, including access, deletion, and opt-out requests. Keep time-stamped consent logs too, including any withdrawals and the exact banner version a person saw at the time.
For vendors, check that contracts limit data use to the services you spelled out. They should also ban the sale or sharing of personal information and give you the right to audit compliance. On the security side, review core safeguards like encryption, multi-factor authentication, and incident response processes.
Related Blog Posts
Get new content delivered straight to your inbox
The Response
Updates on the Reform platform, insights on optimizing conversion rates, and tips to craft forms that convert.
Drive real results with form optimizations
Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.

.webp)


