Compare jurisdictions

Side-by-side view of the obligations each covered law imposes, grouped by category. Use this to spot where requirements overlap (one well-written control often satisfies multiple jurisdictions).

Category
πŸ‡ͺπŸ‡ΊEuropean Union / EEA
πŸ‡¬πŸ‡­Ghana
πŸ‡°πŸ‡ͺKenya
πŸ‡³πŸ‡¬Nigeria
πŸ‡ΊπŸ‡ΈUnited States (California)
Governance & Accountability
  • GDPR-Art-37 Appoint a Data Protection Officer (DPO) where required

    A DPO is required for public authorities, large-scale monitoring, or large-scale special-category data processing.

    GDPR Β· Arts. 37-39

  • GDPR-Art-5 Adhere to the principles of processing

    Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, accountability.

    GDPR Β· Art. 5

  • GH-Principles Apply the eight data protection principles

    Accountability, lawfulness, specification of purpose, compatibility of further processing, quality, openness, safeguards, data subject participation.

    Ghana DPA 2012 Β· Act 843 Β§17

  • NG-DPO Appoint a Data Protection Officer where required

    Controllers of major importance and processors of high-risk data must appoint a DPO and publish their contact.

    Nigeria NDPA 2023 Β· NDPA Β§32

  • NG-Principles Observe principles of personal data processing

    Lawfulness, fairness, transparency, purpose specification, accuracy, storage limitation, integrity and confidentiality, accountability.

    Nigeria NDPA 2023 Β· NDPA Β§24

β€”
Lawful basis & consent
  • GDPR-Art-6 Establish a lawful basis for each processing activity

    Identify and document one of the six lawful bases for every processing activity (consent, contract, legal obligation, vital interests, public task, legitimate interests).

    GDPR Β· Art. 6

  • GH-Consent Obtain consent or rely on a lawful processing ground

    Processing requires consent or another lawful ground (contract, legal obligation, vital interests, public interest, legitimate interests).

    Ghana DPA 2012 Β· Act 843 Β§20

β€”
Transparency & notices
  • GDPR-Art-12 Provide transparent information to data subjects

    Provide a concise, intelligible privacy notice covering identity of controller, purposes, legal basis, recipients, retention, rights, and contact for the DPO.

    GDPR Β· Arts. 12-14

Data subject rights
  • GDPR-Art-15 Honor data subject rights within one month

    Access, rectification, erasure, restriction, portability, objection, and opt-out of automated decisions must be processed within one calendar month (extendable by two months for complexity).

    GDPR Β· Arts. 15-22

  • CCPA-OptOut Provide a "Do Not Sell or Share My Personal Information" link

    Businesses must provide a clear, conspicuous Do-Not-Sell/Share link and honor Global Privacy Control signals.

    CCPA/CPRA Β· Β§1798.135

  • CCPA-Rights Honor consumer rights to know, delete, correct, and limit

    Within 45 days (extendable by 45): access, deletion, correction, and limit use of sensitive personal information.

    CCPA/CPRA Β· Β§1798.105-.125

Security of processing
  • GDPR-Art-32 Implement appropriate technical and organisational measures (TOMs)

    Encryption, pseudonymisation, availability/integrity, regular testing, and ability to restore availability.

    GDPR Β· Art. 32

  • GH-Security Safeguard data against loss and unauthorised access

    Reasonable technical and organisational measures to preserve integrity and confidentiality of personal data.

    Ghana DPA 2012 Β· Act 843 Β§28

β€”
  • CCPA-Security Implement reasonable security procedures

    Protect personal information from unauthorised access, destruction, use, modification, or disclosure.

    CCPA/CPRA Β· Β§1798.100(e)

Breach notification
  • GDPR-Art-33 Breach notification within 72 hours

    Personal data breaches must be notified to the supervisory authority within 72 hours of becoming aware, and affected data subjects notified if high risk.

    GDPR Β· Arts. 33-34

β€”
  • KE-Breach Notify the ODPC of breaches within 72 hours

    Controllers must notify the ODPC within 72 hours of becoming aware; data subjects where there is real risk of harm.

    Kenya DPA 2019 Β· DPA Β§43

β€”
International transfers
  • GDPR-Chap-V Use a valid transfer mechanism for data leaving the EEA

    Transfers outside the EEA require an adequacy decision, SCCs, BCRs, or a valid derogation; complete a Transfer Impact Assessment where applicable.

    GDPR Β· Arts. 44-50

β€”
DPIA / Risk assessment
  • GDPR-Art-35 Perform DPIA for high-risk processing

    A Data Protection Impact Assessment is mandatory for processing likely to result in high risk to rights and freedoms (profiling, large-scale special category, children's data, public monitoring).

    GDPR Β· Art. 35

β€” β€” β€”
Processors & sub-processors β€” β€” β€” β€”
  • CCPA-Contracts Flow-down contractual terms to service providers and contractors

    Written contracts with required clauses (purpose limitation, no sale, audit rights).

    CCPA/CPRA Β· Β§1798.100(d)

Record of processing
  • GDPR-Art-30 Maintain Records of Processing Activities (ROPA)

    Controllers and processors must maintain a written register of processing activities listing purposes, categories of data and subjects, recipients, transfers, retention, and security measures.

    GDPR Β· Art. 30

β€” β€” β€”
Special categories / children β€” β€” β€” β€”
  • CCPA-Sensitive Provide "Limit Use" for Sensitive Personal Information

    Consumers may direct businesses to limit use of sensitive PI to what is necessary to perform services.

    CCPA/CPRA Β· Β§1798.121

Regulator registration β€”
  • KE-Registration Register as data controller or processor with the ODPC

    Controllers and processors above a prescribed threshold must register with the ODPC (renewable every 2 years).

    Kenya DPA 2019 Β· DPA Β§18

β€” β€”

Each obligation links to the official law text or the regulator that imposes it, with the precise article/section shown beside it. Sourced from the same content engine that powers the assessment. Cells marked "β€”" mean the law in that column has no specific requirement in that category β€” not that anything is exempt. Each framework's last-reviewed date, source version and change history are on the methodology page.