Privacy regulation has expanded substantially, and the rights it creates are exercised by a small fraction of the people who hold them.

The two models

Comprehensive frameworks regulate all processing of personal data across sectors.

Sectoral frameworks regulate specific areas — health, finance, children — leaving the rest largely unregulated.

Which produces very different coverage, and comprehensive frameworks have spread as jurisdictions have adopted similar approaches.

The core principles

Most comprehensive frameworks share a similar set.

Lawfulness, requiring a legal basis for processing.

Purpose limitation, meaning data collected for one purpose should not be used for an unrelated one.

Data minimisation, collecting only what is necessary.

Accuracy.

Storage limitation, not keeping data indefinitely.

Security.

And accountability, requiring organisations to demonstrate compliance.

Legal bases

Consent is one basis among several, and it is frequently assumed to be the only one.

Others generally include contractual necessity, legal obligation, vital interests, public task and legitimate interests.

Which means much processing occurs lawfully without consent, and the consent banners people encounter reflect a specific choice rather than a universal requirement.

Individual rights

Access, allowing a person to obtain a copy of their data.

Rectification of inaccurate data.

Erasure in defined circumstances.

Restriction of processing.

Portability, receiving data in a transferable format.

And objection to certain processing.

Which are exercisable free of charge in most frameworks, with defined response times, and are used by a small minority.

The access request

The most powerful and least used.

Requesting your data from an organisation reveals what they hold, which is frequently more than expected.

Which is a straightforward written request, and organisations must respond within a specified period.

Journalists and researchers have used these to establish practices that were not otherwise disclosed.

Enforcement

Regulators can investigate, order changes and impose penalties, with maximum penalties set as a proportion of turnover in several frameworks.

Which are substantial in principle, and enforcement capacity is generally far below the volume of activity regulated.

Cross-border enforcement mechanisms have proven slow in practice, with cases taking years.

International transfers

Frameworks generally restrict transferring data to jurisdictions without adequate protection.

Which has produced a series of legal instruments, several of which have been invalidated by courts on the basis that receiving-country surveillance law provided inadequate protection.

The resulting uncertainty is a substantial practical issue for organisations operating internationally.

Children

Additional protections apply in most frameworks, including age thresholds for consent and, in some, design requirements for services likely to be accessed by children.

Age assurance mechanisms are the practical difficulty, since verifying age generally requires collecting more data.

What to actually do

Making an access request to any organisation you deal with is informative and free.

Complaints to the regulator are also free, and they are a significant input into enforcement priorities.

Automated decision-making

Several frameworks provide rights regarding decisions made solely by automated means with significant effects.

Which generally include a right to human review and to an explanation of the logic involved.

The scope of the explanation right has been contested, since meaningful explanation of complex models is technically difficult.

Breach notification

Requirements to notify regulators and, where risk is high, affected individuals.

Which has produced substantially more public knowledge of breaches than existed previously.

Timeframes are short in most frameworks, generally days rather than weeks.

Data brokers

Organisations collecting and selling personal data without a direct relationship with the individuals concerned.

Which are covered by comprehensive frameworks and largely unregulated under sectoral ones.

Registration requirements and deletion mechanisms have been introduced in some jurisdictions specifically to address this.

Consent in practice

The mechanism most people encounter and among the least effective.

Research consistently finds that consent notices are not read, are not understood and do not produce informed choice.

Which has led to interest in design requirements, default settings and restrictions on manipulative interface patterns.

Several regulators have taken enforcement action over consent interface design specifically.

Anonymisation

Data that cannot identify individuals generally falls outside these frameworks.

Which makes the standard for anonymisation consequential, and research has repeatedly demonstrated re-identification of supposedly anonymised datasets.

Regulatory guidance therefore treats anonymisation as demanding rather than as a simple removal of names.

Practical steps

Reviewing app permissions, reviewing account privacy settings, and checking which third parties have authorised access all take minutes.

Which addresses more actual exposure than reading privacy policies does.

Enforcement priorities

Regulators publish strategies indicating what they will focus on.

Which is worth reading for anyone in a regulated organisation, and it indicates what complaints are likely to be acted on.

Resource constraints mean most complaints do not result in investigation, and patterns of complaint drive priorities.

The compliance industry

Substantial professional infrastructure has developed around these frameworks.

Which has produced genuine improvement in organisational practice and a considerable volume of activity that is procedural rather than protective.

Regulators have noted that documented compliance is not the same as actual data protection.