Key Takeaways - International Data Security Laws & Regulations
- International data security laws have extraterritorial reach. They apply to organizations worldwide that process data of their residents.
- The EU GDPR is the most impactful, with fines up to 4% of global annual revenue or €20M (whichever is higher).
- These represent a mix of statutory and regulatory obligations depending on jurisdiction. All carrying significant penalties.
- ComplianceForge products include Data Privacy Program (DPP) documentation specifically designed for GDPR and international privacy compliance.
- The SCF maps controls to international requirements, enabling unified compliance across jurisdictions.
OverviewWhy Does Your Business Need A Cybersecurity & Data Protection Program?
The reason is simple - information security policies and standards are entirely focused on protecting your business! Professionally written cybersecurity policies provide the necessary steps to document the due care and due diligence your business needs to prove compliance with information security laws and industry regulations. While you spend thousands of dollars a year on business liability insurance, purchasing an ISO 27002-based Cybersecurity & Data Protection Program (CDPP) from ComplianceForge.com might be the most cost-effective protection you can provide for your company.
Common QuestionsFrequently-Asked Questions
Here are answers to common questions about international data security laws:
Does the UK GDPR apply to companies outside the UK?
Yes, the UK Information Commissioner's Office explains that the UK GDPR applies to controllers and processors based outside the UK when their processing relates to offering goods or services to individuals in the UK or monitoring the behavior of individuals in the UK. The UK GDPR is the version of the GDPR retained in UK law after Brexit, and it sits alongside an amended Data Protection Act 2018. It started from the same principles, rights and obligations as the EU GDPR, but the two regimes are now separate and can be amended independently.
How fast must data breaches be reported under the GDPR and UK GDPR?
Both laws require a controller to notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. Under the UK GDPR, the report goes to the Information Commissioner's Office. Processors must notify their controller without undue delay, and controllers must tell affected individuals directly when a breach is likely to result in a high risk to their rights and freedoms.
Why do international companies use ISO 27002 for security policies?
Many international companies use ISO/IEC 27002 because it is an international standard that provides a reference set of information security controls, rather than a single country's law, so it works as a common baseline across jurisdictions. The current edition was published in 2022. ComplianceForge offers an ISO 27002-based Cybersecurity & Data Protection Program (CDPP) with editable policies and standards for documenting due care and due diligence, which makes it a good fit for international companies.
How can one control set cover data protection laws in multiple countries?
A metaframework maps one set of controls to many laws so overlapping requirements are implemented once. The Secure Controls Framework (SCF) is free under a Creative Commons license and maps more than 1,500 controls across 34 domains to over 200 laws, regulations and frameworks, including international requirements. ComplianceForge is an SCF Licensed Content Provider, and we've aligned our Security, Compliance & Resilience Program (SCRP) to SCF controls.
What are the maximum fines under international data protection laws?
The EU GDPR sets the highest-profile ceiling: up to EUR 20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, for violations such as breaching the basic processing principles. Violations of controller and processor obligations, including security of processing and breach notification, can reach EUR 10 million or 2%. In the UK, the ICO states that failing to report a notifiable breach can bring a fine of up to £8.7 million or 2% of global turnover.