TY - GEN
T1 - Local Privacy Laws in a Globalized World
AU - Sharma, Shantanu
AU - Myers, Ethan
AU - De Carli, Lorenzo
AU - Banerjee, Ritwik
AU - Ray, Indrakshi
N1 - Publisher Copyright:
© 2026 Owner/Author.
PY - 2026/6/22
Y1 - 2026/6/22
N2 - Personal data has emerged as a highly valuable yet sensitive asset that drives business decisions, enables targeted advertising, and generates substantial revenue for companies, while simultaneously facilitating invasive monitoring of users. In recent years, research on digital privacy violations, including undue access, collection, and sharing of user data, has grown significantly. Much of this research adopts the European General Data Protection Regulation (GDPR) as the primary reference framework. This is reasonable, as GDPR was a pioneering legislation, and many of its stipulations are clear and unambiguous. However, we argue that focusing solely on GDPR (and a small set of other Western regulatory frameworks) ignores privacy-related concerns, attitudes, and problems faced by users from other locales, creating a significant research blind spot. This work systematically normalizes the heterogeneous legal requirements of multiple data protection laws into a unified abstraction aligned with the data lifecycle, which forms the foundation for the implementation of such regulations. We further investigate the implications of these laws on different stakeholders, including users, organizations, and governments. Overall, this work aims to broaden the digital privacy research community's perspective and to serve as a set of guiding principles for developing technological privacy solutions spanning multiple countries.
AB - Personal data has emerged as a highly valuable yet sensitive asset that drives business decisions, enables targeted advertising, and generates substantial revenue for companies, while simultaneously facilitating invasive monitoring of users. In recent years, research on digital privacy violations, including undue access, collection, and sharing of user data, has grown significantly. Much of this research adopts the European General Data Protection Regulation (GDPR) as the primary reference framework. This is reasonable, as GDPR was a pioneering legislation, and many of its stipulations are clear and unambiguous. However, we argue that focusing solely on GDPR (and a small set of other Western regulatory frameworks) ignores privacy-related concerns, attitudes, and problems faced by users from other locales, creating a significant research blind spot. This work systematically normalizes the heterogeneous legal requirements of multiple data protection laws into a unified abstraction aligned with the data lifecycle, which forms the foundation for the implementation of such regulations. We further investigate the implications of these laws on different stakeholders, including users, organizations, and governments. Overall, this work aims to broaden the digital privacy research community's perspective and to serve as a set of guiding principles for developing technological privacy solutions spanning multiple countries.
KW - data protection laws
KW - user privacy
UR - https://www.scopus.com/pages/publications/105044147890
U2 - 10.1145/3800506.3803491
DO - 10.1145/3800506.3803491
M3 - Conference contribution
AN - SCOPUS:105044147890
T3 - CODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
SP - 193
EP - 204
BT - CODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
PB - Association for Computing Machinery, Inc
T2 - 16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026
Y2 - 23 June 2026 through 25 June 2026
ER -