Privacy Risk Intelligence
BLOG
Privacy Risk Intelligence

20 States. 144 Countries. Why the Compliance Map Breaks Inside-Out.

Bill Porter
May 19, 2026
7 min read
Post hero
FULL ARTICLE
On this page
20 States. 144 Countries. Why the Compliance Map Breaks Inside-Out.

In 2018, there was one US state comprehensive privacy law. GDPR was new and the enforcement record was thin.

By 2026, twenty US states have enacted comprehensive privacy legislation. The EU has added the AI Act, ePrivacy enforcement has intensified, and 144 countries now maintain some form of national privacy framework. The compliance map has not simply expanded. It has become three-dimensional: overlapping jurisdictions, inconsistent definitions of the same terms, conflicting requirements for the same data practices.

What Jurisdictional Complexity Actually Means in Practice

The challenge is not simply that there are more laws. It is that the same digital behavior carries different legal characterizations depending on where it is observed.

The sale definition problem. Under the CCPA, a "sale" of personal information includes sharing data with a third party for valuable consideration: broad enough to capture many standard advertising data flows. Under Virginia's CDPA, the definition is narrower. The same tag deployment may constitute a sale in California, a targeted advertising use in Virginia, and a standard analytics operation in Texas.

The consent standard problem. GDPR requires freely given, specific, informed, unambiguous consent for non-essential cookies. Brazil's LGPD applies similar standards. California's CPRA requires opt-out for sale and sharing, but opt-in for sensitive data. A single consent mechanism cannot satisfy all of these standards simultaneously.

The data transfer problem. GDPR's requirements for transfers to third countries are extensive and evolving. Brazil, India, South Korea, and an expanding set of countries have enacted transfer restrictions of varying stringency. A US company loading a page for a user in Germany may trigger transfer obligations to the US, to any third-party vendors receiving data, and to any subprocessors those vendors use.

How Enforcement Authorities Use Jurisdictional Variation

Regulators are sophisticated about jurisdictional variation. They apply it strategically. The EDPB's coordinated enforcement actions increasingly target behavior that violates the strictest interpretation of GDPR, knowing the same behavior may be permissible under a less stringent regime.

State attorneys general coordinate through the National Association of Attorneys General. Joint enforcement actions are becoming more common, specifically targeting behavior that violates multiple state frameworks at once. The $25.6M multistate settlement with Blackbaud in 2024 involved 49 attorneys general. Plaintiff attorneys have become expert jurisdictional shoppers; the same underlying data practice generates different exposure depending entirely on which jurisdiction's law is applied.

The Visibility Problem

Most privacy programs know what laws apply to their company. They do not know what their company's observable behavior looks like from each jurisdiction where those laws apply. These are not the same question.

A company knows it is subject to GDPR because it has European customers. What it may not know is that its cookie consent mechanism, as observed by a user loading the page from Germany, presents pre-ticked boxes for analytics cookies: a direct violation of EDPB guidance. The CMP was configured correctly in the admin panel. The observed behavior in that jurisdiction does not match the configuration.

What Jurisdictional Outside-In Assessment Produces

An outside-in assessment conducted across jurisdictions answers questions that inside-out documentation cannot: What does the consent mechanism actually present to users in Germany vs. California vs. Texas? Which third parties receive data when a user in France loads the homepage? Does the opt-out flow work as disclosed, for users in California? Are transfer mechanisms in place for data flows triggered by a UK user session?

Each question has a different answer depending on jurisdiction. Each answer constitutes the factual record that enforcement is built on. The privacy program that can answer them has genuine visibility into its jurisdictional exposure. The program that cannot is operating on documentation that may not reflect observable reality.

Twenty state laws and 144 national frameworks are not a documentation problem. They are a visibility problem. The compliance map is not getting simpler. The question is whether your view of the territory matches the map.

This is some text inside of a div block.
Author
Bill Porter
Head of Marketing
BA Communication Saint Mary's College of California
KEEP READING

More from the blog

Opt-Out Signal Honored