Privacy Law Applicability Checker

Published July 23, 2026

Different privacy laws apply depending on where your users are located and what kind of data you collect, not where your business is based. Select your platform and answer five yes-or-no questions below to see exactly which regulations you need to comply with.

Do you have users in the EU/EEA?
Do you have users in California?
Do you have users in Canada?
Do you have users in Brazil?
Do you knowingly collect data from children under 13?

How to Use This Tool

Start by selecting your platform type from the dropdown: website, iOS app, Android app, or both. Then answer each of the five questions by toggling Yes or No. The checker uses a simple rule table: each region you select maps to the privacy law that governs personal data in that jurisdiction. Hit "Check Applicable Laws" to see your results. Each law in your checklist includes a brief description of what it requires. If you're still working out whether your project needs a privacy policy in the first place, our breakdown of when a policy becomes a legal requirement covers that groundwork. Once you know a law applies to you, use the results below as a starting point, then generate your privacy policy to create a compliant document tailored to your specific setup.

GDPR: The European Union's Data Protection Regulation

The GDPR applies to any organization, anywhere in the world, that processes the personal data of people located in the EU or EEA — either by offering them goods or services or by monitoring their behavior, such as through analytics or ad tracking. There is no revenue or user-count threshold: a single EU visitor whose data you collect is enough to bring the regulation into play if you're targeting that market. Once it applies, your privacy policy must state the lawful basis for each processing activity, list the categories of data collected and how long you retain them, name a Data Protection Officer if you're required to appoint one, describe any international data transfer safeguards, and explain how users can exercise their rights to access, correct, delete, and port their data. Breaches affecting EU residents must be reported to the relevant supervisory authority within 72 hours.

UK GDPR: The Post-Brexit Regime for British Users

After Brexit, the UK retained the EU GDPR's text almost verbatim through the Data Protection Act 2018, creating a separate but nearly identical regime enforced by the Information Commissioner's Office rather than an EU supervisory authority. It applies the same way the EU version does: based on where your users are, not where your business is registered, with no minimum revenue or user count required to trigger it. Businesses with no UK establishment that target UK residents may also need to appoint a UK representative. The disclosure requirements mirror the EU GDPR closely — lawful basis, data categories, retention periods, transfer safeguards, and user rights — so a policy written for EU compliance covers most UK obligations too. This checker's "EU/EEA" question is currently the closest proxy for UK users as well; answer yes if any of your users are in the UK, since the two regimes share the same disclosure baseline.

CCPA/CPRA: California's Consumer Privacy Law

The CCPA, as amended by the CPRA, applies to for-profit businesses that do business in California and meet at least one of three thresholds: more than $26.625 million in annual gross revenue, buying or selling the personal information of 100,000 or more California consumers or households per year, or deriving at least half of annual revenue from selling or sharing personal information. If you meet any one of these, your privacy policy must disclose the categories of personal information collected and their purpose, list any categories sold or shared and to whom, state your retention period, and include a working "Do Not Sell or Share My Personal Information" (or "Your Privacy Choices") link. You must also honor consumer requests to know, delete, correct, and opt out of the sale or sharing of their data, plus additional protections for sensitive personal information.

PIPEDA: Canada's Federal Privacy Law

PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity involving Canadian residents, including businesses based outside Canada that do business with them. There's no revenue or user-volume threshold — commercial handling of personal data is what triggers it, though Quebec, British Columbia, and Alberta each have their own substantially similar provincial laws that can take precedence for organizations operating solely within those provinces. Your privacy policy needs to name a designated individual accountable for compliance, explain the purposes for which you collect personal information in language a reasonable person would understand, describe how you obtain meaningful consent, and outline how individuals can access and correct their own records.

LGPD: Brazil's General Data Protection Law

Brazil's Lei Geral de Proteção de Dados applies to any organization, wherever it's based, that processes the personal data of people located in Brazil, collects data within Brazil, or offers goods or services to Brazilian residents. Like the GDPR it's modeled on, there's no minimum revenue or user threshold — a single Brazilian user can be enough if you're offering them a product or service. A compliant privacy policy must state the legal basis for processing, describe the purpose and any third parties data is shared with, set out retention periods, and explain how users can exercise their rights to confirmation, access, correction, anonymization, portability, and deletion. Organizations processing data at meaningful scale must also name an encarregado (data protection officer) and publish their contact details.

COPPA: U.S. Rules for Children's Data

COPPA applies to operators of websites or apps directed at children under 13, and to general-audience services that have actual knowledge they're collecting personal information from users under 13 — audience and data practices trigger it, not revenue or company size. If it applies to you, your privacy policy must clearly describe what information you collect from children, how you use it, and whether you disclose it to third parties, and you must obtain verifiable parental consent before collecting that data. Parents must also be given a way to review the information collected about their child and request its deletion. The FTC actively enforces COPPA, and penalties for violations can run into the millions of dollars per case.

Why Knowing Your Applicable Laws Matters

Privacy laws apply based on where your users are, not where your company is registered. An app developed in Texas that has a single user in Munich must comply with the GDPR. A website hosted in Canada that gets visitors from Sao Paulo falls under Brazil's LGPD. Getting this wrong is not a theoretical risk: the Irish Data Protection Commission fined WhatsApp 225 million euros in 2021 for inadequate transparency, and Google received a 50 million euro GDPR fine from France's CNIL for insufficient consent disclosures.

Beyond fines, app stores enforce compliance at the listing level. Google Play requires a privacy policy URL and a completed Data Safety section for every published app. Apple mandates a privacy policy link in App Store Connect and rejects submissions that don't include one. Knowing which laws apply is the first step to getting both your legal obligations and your store listing requirements right.

Once you know which laws cover your user base, the next step is building a privacy policy that addresses each one. You can learn how to write a privacy policy for your app with our step-by-step guide, or jump straight to the generator to create one in minutes.

Frequently Asked Questions

Do privacy laws apply even if my business is not in the same country as my users?

Yes. Most modern privacy laws, including the GDPR, CCPA, and LGPD, apply based on where the user is located, not where the business is incorporated. If your app or website is accessible to people in a regulated jurisdiction, that jurisdiction's law applies to you.

What happens if I don't comply with an applicable privacy law?

Consequences range from fines to app removal. GDPR penalties can reach 20 million euros or 4% of global annual revenue, whichever is higher. The CCPA allows statutory damages of $100 to $750 per consumer per incident. Google Play and the App Store can also suspend or remove apps that lack required privacy disclosures.

Is this checker a substitute for legal advice?

No. This tool provides a general overview based on the regions and data practices you select. It does not account for sector-specific regulations like HIPAA or state-level laws beyond California. For apps handling sensitive data (health, financial, children's information), consult a qualified privacy attorney.

Can multiple privacy laws apply to the same app at once?

Absolutely. An app with users in the EU, California, and Brazil must comply with the GDPR, CCPA/CPRA, and LGPD simultaneously. Each law has its own requirements for disclosure, consent, and user rights. A comprehensive privacy policy should address all applicable laws in a single document.

Does COPPA apply if my app is not directed at children?

COPPA applies if you have actual knowledge that you are collecting data from children under 13, even if your app is not specifically designed for them. If your app attracts a significant child audience or you knowingly collect data from minors, COPPA obligations apply regardless of your intended audience.