{
  "dataset": "DataExos Legal Landscape - Layer-1 Verified Anchor Dataset",
  "publication": "Navigating the Legal Landscape: AI & Data Regulation (edition 2)",
  "publisher": "DataExos, LLC",
  "edition": 2,
  "verified_through": "2026-08-28",
  "primary_retrievals_through": "2026-08-28",
  "supersedes": "edition 1 (as of 2026-07-23; withdrawn from distribution)",
  "notice": "General information only - not legal advice, a legal opinion, or a compliance determination. A selective, dated summary; not tailored to any person's facts and not the sole basis for action. Verify current primary authorities and obtain qualified legal advice in the relevant jurisdiction before relying. Nothing in this dataset excludes any right or liability that applicable law does not permit to be excluded. Full notice: the 'Important Legal, Reliance, and Liability Notice' in the companion PDF, and https://www.dataexos.com.",
  "license_note": "Redistribution of the complete, unaltered publication and dataset, with the notice, edition date, and attribution intact, is permitted. Preserve title, edition date, attribution, citations, material qualifications, and the notice; do not present as legal advice or alter misleadingly. See the PDF's Redistribution and version control section.",
  "scope": {
    "anchors": [
      "European Union",
      "United Kingdom",
      "United States",
      "China",
      "Canada",
      "Brazil",
      "India",
      "South Korea"
    ],
    "dimensions": [
      "data_protection",
      "ai_regulation",
      "cross_border_transfer",
      "data_localization"
    ],
    "out_of_scope_dropped": [
      "sanctions",
      "export_controls",
      "anti_bribery",
      "IP",
      "tax/PE",
      "employment",
      "cloud_regions",
      "rule_of_law",
      "corruption"
    ]
  },
  "status_vocabulary": [
    "in force",
    "enacted-not-in-force",
    "rules pending",
    "proposed",
    "withdrawn",
    "published gap"
  ],
  "source_tiers": {
    "T0": "primary instrument read directly",
    "T1": "official/institutional source",
    "T2": "identified secondary authority (flagged; capped at medium confidence)"
  },
  "date_fields": "Where applicable each record carries four separate dates: enacted, in_force (entry into force), rules_effective (application / transposition / rules commencement), as_of_access (when the load-bearing source was originally read). A separate last_verified field records the most recent verification event for the record. A blank field means not applicable or not separately verified - never a conflation.",
  "revision_summary": "Edition 2 corrections (independent verification pass through 2026-08-27 + primary retrievals 2026-08-28): 4 cells materially corrected (UK AI status; US, China, and India cross-border transfer), 11 cells qualified or re-attributed, 2 treaty-layer statements corrected (CoE Framework Convention entry-into-force; Pax Silica signatories), sourcing representation corrected. Tier split: 14 T0, 10 T1, 6 T2 across 30 sourced cells + 2 published gaps.",
  "records": [
    {
      "id": "EU-DP",
      "jurisdiction": "European Union",
      "dimension": "data_protection",
      "instrument": "General Data Protection Regulation — Regulation (EU) 2016/679 (GDPR)",
      "article_section": "Regulation as a whole; Art. 3 (territorial scope)",
      "status": "in force",
      "provision": "GDPR has applied since 25 May 2018. Enforcement is decentralised: GDPR Art. 51 requires each Member State to provide for one or more independent supervisory authorities (Germany, for example, has several), coordinated through the European Data Protection Board; there is no single EU-wide regulator for private-sector processing.",
      "dates": {
        "enacted": "2016-04-27",
        "in_force": "2016-05-24",
        "rules_effective": "2018-05-25 (date of application)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
      "notes": "A contested 'Digital Omnibus' GDPR-reform proposal (published 19 Nov 2025) remains PROPOSED and is not part of this in-force record; EDPB/EDPS objected in Joint Opinion 2/2026. Nothing in that strand is operative and it must not be described in requirement language."
    },
    {
      "id": "EU-AI",
      "jurisdiction": "European Union",
      "dimension": "ai_regulation",
      "instrument": "Artificial Intelligence Act — Regulation (EU) 2024/1689",
      "article_section": "Art. 113 (phased application); Art. 5 (prohibited practices); Chapter V (GPAI)",
      "status": "in force",
      "provision": "The first comprehensive horizontal AI statute. Risk-tiered (prohibited / high-risk / limited-risk transparency / minimal), with a separate horizontal layer for general-purpose AI. Obligations phase in over several years.",
      "dates": {
        "enacted": "2024-06-13 (adopted); published OJ 2024-07-12",
        "in_force": "2024-08-01",
        "rules_effective": "Prohibited practices + AI literacy: 2 Feb 2025 (in force). GPAI + governance: 2 Aug 2025 (in force). General applicability incl. Art. 50 transparency: 2 Aug 2026. High-risk Annex III standalone: 2 Dec 2027. High-risk product-embedded: 2 Aug 2028.",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
      "secondary_urls": [
        "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ%3AL_202601744"
      ],
      "notes": "The 'AI Omnibus' amendment is in force: Regulation (EU) 2026/1744, published OJ 2026-07-24, consolidated into the AI Act from 2026-07-27. The deferred high-risk dates it sets - 2 Dec 2027 (Annex III standalone) and 2 Aug 2028 (product-embedded) - are operative. Transitional rule: providers of relevant synthetic-content-generating systems placed on the market before 2 Aug 2026 have until 2 Dec 2026 to comply with Art. 50(2); this is a specific transitional provision, not a blanket postponement of Art. 50. In-force layers: prohibitions + AI literacy 2 Feb 2025; GPAI + governance 2 Aug 2025; general applicability incl. Art. 50 transparency 2 Aug 2026. (Edition 1 recorded the amendment as agreed-but-unpublished as of 2026-07-23 - correct on that date, superseded the next day; full history in the revision record.)"
    },
    {
      "id": "EU-XBORDER",
      "jurisdiction": "European Union",
      "dimension": "cross_border_transfer",
      "instrument": "GDPR Chapter V (Arts. 44-50)",
      "article_section": "Chapter V; Art. 45 (adequacy); Art. 46 (SCC/BCR); Art. 49 (derogations)",
      "status": "in force",
      "provision": "Transfers to third countries permitted via adequacy decision, appropriate safeguards (SCCs, BCRs), or Art. 49 derogations. For US transfers the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) is in force and has not been repealed or annulled.",
      "dates": {
        "enacted": "",
        "in_force": "2016-05-24 (GDPR entry into force)",
        "rules_effective": "Chapter V applies from 2018-05-25; EU-US DPF adequacy adopted 10 Jul 2023",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
      "notes": "Live-verified on the Commission adequacy page (2026-07-23): current adequacy holders include Andorra, Argentina, Brazil, Canada (commercial), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, United States (EU-US DPF), Uruguay, European Patent Organisation. Litigation risk to the DPF (Latombe appeal, Case C-703/25 P, reported pending) exists but the DPF is valid unless repealed or annulled — an accurate statement, not a prediction."
    },
    {
      "id": "UK-DP",
      "jurisdiction": "United Kingdom",
      "dimension": "data_protection",
      "instrument": "UK GDPR + Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (2025 c.18)",
      "article_section": "DUAA 2025 Part 5; new Arts. 22A-22D (automated decision-making); Art. 12A (DSAR clock)",
      "status": "in force",
      "provision": "UK GDPR + DPA 2018 remain the regime; the DUAA 2025 substantially amended it. Principal data-protection reforms commenced 5 February 2026, including replacing the Art. 22 prohibition on solely-automated decision-making with a permission-plus-safeguards model, and adding 'recognised legitimate interests' requiring no balancing test. Higher-tier penalty ceiling: up to £17.5m or 4% of global turnover.",
      "dates": {
        "enacted": "2025-06-19 (Royal Assent of DUAA 2025)",
        "in_force": "Base UK GDPR/DPA 2018 in force; DUAA data-protection provisions commenced 5 Feb 2026",
        "rules_effective": "Staged: 20 Aug 2025, 4/30 Sep 2025, 5 Feb 2026 (principal reforms, SI 2026/82), 19 Jun 2026 (data-subject complaints, s.103/Sch.10)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.legislation.gov.uk/uksi/2026/82/made",
      "notes": "Commencement is by SI (SI 2026/82 made 29 Jan 2026 appoints 5 Feb 2026 and 19 Jun 2026) — Royal Assent (19 Jun 2025) is not commencement. Penalty ceiling figures sourced T2 (DLA Piper, 24 Feb 2026); they belong to UK GDPR/DPA 2018/PECR and are not imported from any other instrument."
    },
    {
      "id": "UK-AI",
      "jurisdiction": "United Kingdom",
      "dimension": "ai_regulation",
      "instrument": "No comprehensive AI statute. Artificial Intelligence (Regulation) Bill [HL] (Private Member's Bill) fell at prorogation of the 2024-26 session.",
      "article_section": "n/a",
      "status": "withdrawn",
      "provision": "No comprehensive horizontal AI statute in force. AI is governed at the point of use through existing regimes and five non-statutory cross-sectoral principles applied by existing regulators (ICO, FCA, PRA, Ofcom, MHRA, CMA). The Artificial Intelligence (Regulation) Bill [HL] fell at prorogation of the 2024-26 parliamentary session and was not pending as of 2026-07-20. It was also not the only AI-related bill of that session: a bill addressing public-authority algorithmic and automated decision-making also existed and likewise fell.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://bills.parliament.uk/bills/3942/news",
      "notes": "Negative claim (no comprehensive AI statute) corroborated by DSIT government response (6 Feb 2024, T1) and CMS Expert Guide (30 Apr 2026, T2). The Bills API (T0) confirms Bill 3942 currentStage='1st reading', isAct=false. A widely-repeated secondary claim that the bill is 'in final stages' conflates it with the earlier 2023-24 bill (Bill 3519) — do not repeat."
    },
    {
      "id": "UK-XBORDER",
      "jurisdiction": "United Kingdom",
      "dimension": "cross_border_transfer",
      "instrument": "UK GDPR transfer regime (adequacy regulations, IDTA, UK Addendum to EU SCCs, BCRs, Art. 49); DUAA 'data protection test'",
      "article_section": "UK GDPR Chapter V as amended by DUAA 2025 Part 5",
      "status": "in force",
      "provision": "Multi-route outbound transfers permitted; DUAA introduced a 'data protection test' (safeguards 'not materially lower than' the UK standard). Inbound from the EU rests on EU adequacy: the Commission renewed the two UK adequacy decisions (GDPR and LED) in December 2025.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "EU adequacy renewed 19 Dec 2025 (Decision (EU) 2025/2574); expires 27 Dec 2031 unless extended",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
      "notes": "Renewal read from Commission Implementing Decision (EU) 2025/2574 itself (OJ L 23 Dec 2025; retrieved from EUR-Lex 28 Aug 2026, on file): adopted 19 Dec 2025; 'This Decision shall expire on 27 December 2031' (Art. 2, replacing Art. 4 of Decision 2021/1772); the 2021 immigration-control exclusion is repealed (Art. 1; recital 37). Outbound named-adequacy country list remains T2 and goes stale; publish the mechanism, not the enumeration."
    },
    {
      "id": "UK-LOCAL",
      "jurisdiction": "United Kingdom",
      "dimension": "data_localization",
      "instrument": "UK GDPR (no localization mandate)",
      "article_section": "n/a",
      "status": "in force",
      "provision": "No explicit data-localization requirement under UK GDPR. Cross-border movement is regulated through the transfer regime rather than by a storage-location mandate. Scope limit: this conclusion is general-purpose only. It rests on a secondary tracker, and sector-specific rules were not surveyed. It must remain narrowly scoped and medium-confidence.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T2",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.dlapiperdataprotection.com/index.html?t=law&c=GB",
      "notes": "Sourced negative resting on DLA Piper (24 Feb 2026): 'No explicit data localization requirement exists under UK GDPR.' T2 only — the negative is affirmatively stated by the tracker, not inferred from silence, but was not confirmed against primary text. Sector-specific residency rules not surveyed."
    },
    {
      "id": "US-DP",
      "jurisdiction": "United States",
      "dimension": "data_protection",
      "instrument": "No comprehensive federal privacy statute; sectoral federal laws + state patchwork",
      "article_section": "HIPAA; GLBA; FCRA; COPPA; FTC Act s.5 (15 U.S.C. 45); state comprehensive laws (e.g. CA CCPA/CPRA)",
      "status": "in force",
      "provision": "There is no comprehensive national privacy law. A sectoral federal regime (HIPAA health, GLBA/FCRA financial, COPPA children, FTC Act s.5 general enforcement) operates alongside a growing state patchwork — 20 states with enacted comprehensive privacy legislation per DLA Piper. The FTC acts as de facto general enforcer; there is no single national DPA.",
      "dates": {
        "enacted": "",
        "in_force": "Sectoral statutes long in force",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T2",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.dlapiperdataprotection.com/index.html?t=law&c=US",
      "notes": "Negative claim ('no comprehensive national privacy law') sourced to DLA Piper (last modified 31 Mar 2026). The underlying sectoral statutes are real T0 federal laws. The count of 20 states is DLA Piper's; the IAPP tracker (member-gated) is the better source — publish 'about 20 states' or re-source before publishing a hard number."
    },
    {
      "id": "US-AI",
      "jurisdiction": "United States",
      "dimension": "ai_regulation",
      "instrument": "No comprehensive federal AI statute; federal executive orders + state statutes (TX TRAIGA, CA TFAIA, CO ADMT)",
      "article_section": "EO 14179; EO 14365; TX HB 149; CA SB 53 (Ch. 138 of 2025); CO SB 26-189",
      "status": "in force",
      "provision": "No comprehensive federal AI statute. The federal layer is executive-order/agency policy (EO 14179 'Removing Barriers to American Leadership in AI', signed 23 Jan 2025; EO 14365 'Ensuring a National Policy Framework for AI', signed 11 Dec 2025, which seeks to preempt/litigate against state AI laws). Binding AI law exists at state level: Texas TRAIGA (HB 149) took effect 1 Jan 2026; California TFAIA (SB 53) frontier-model transparency is operative; Colorado's ADMT regime (SB 26-189, signed 14 May 2026) defers developer obligations to 1 Jan 2027.",
      "dates": {
        "enacted": "EO 14179 signed 2025-01-23 (pub. 2025-01-31); EO 14365 signed 2025-12-11 (pub. 2025-12-16); TX HB 149; CA SB 53 approved 2025-09-29; CO SB 26-189 signed 2026-05-14",
        "in_force": "TX HB 149: 1 Jan 2026. CA SB 53: operative (see conflict note). EOs: on signing.",
        "rules_effective": "CO SB 26-189 developer obligations: 1 Jan 2027 (enacted-not-in-force)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.govinfo.gov/content/pkg/FR-2025-12-16/pdf/2025-23092.pdf",
      "notes": "EOs 14179/14365 and TX HB 149 read directly from primary text (Federal Register / Texas Legislature). CA SB 53 commencement is contested between 'effective on approval' (29 Sep 2025) and the California default of 1 Jan 2026 — record both, do not pick. CalCompute provisions have a separate appropriation trigger. State penalty figures (TX $10k-$200k tiers; CA up to $1m/violation) are drawn from each statute's own text and not cross-imported. Direction for the jurisdiction as a whole is genuinely two-signed (federal deregulatory/preemptive vs state tightening) — describe as in flux, not as tightening or loosening."
    },
    {
      "id": "US-XBORDER",
      "jurisdiction": "United States",
      "dimension": "cross_border_transfer",
      "instrument": "No omnibus outbound-transfer regime; targeted DOJ Data Security Program (28 C.F.R. Part 202); inbound EU-US Data Privacy Framework",
      "article_section": "EU-US DPF adequacy decision (EU) 2023/1795",
      "status": "in force",
      "provision": "The United States has no omnibus GDPR-style outbound personal-data transfer regime. Targeted national-security restrictions nevertheless apply under the DOJ Data Security Program (28 C.F.R. Part 202, effective 8 April 2025), which prohibits or restricts specified covered transactions involving bulk US sensitive personal data - or US government-related data regardless of volume - and countries of concern or covered persons. The EU-US DPF, SCCs, and BCRs remain relevant to transfers originating in the EEA; the EU General Court upheld the DPF on 3 September 2025 in Latombe.",
      "dates": {
        "enacted": "",
        "in_force": "DPF adequacy 10 Jul 2023; upheld (General Court) 3 Sep 2025",
        "rules_effective": "",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T2",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
      "secondary_urls": [
        "https://www.justice.gov/opa/pr/justice-department-implements-critical-national-security-program-protect-americans-sensitive"
      ],
      "notes": "DPF live-confirmed on the EU adequacy page (2026-07-23): 'United States (commercial organisations participating in the EU-US Data Privacy Framework)'. Latombe judgment date (3 Sep 2025) and appeal number (C-703/25 P) are T2/T4-reported, not verified against the CJEU register. Named structural risks to DPF durability (PCLOB quorum; FISA 702 status) are real but reported and should not be stated as fact."
    },
    {
      "id": "US-LOCAL",
      "jurisdiction": "United States",
      "dimension": "data_localization",
      "instrument": "No general commercial localization mandate; sectoral government (FedRAMP/GovCloud)",
      "article_section": "n/a",
      "status": "in force",
      "provision": "No general commercial data-localization mandate. Geographic or personnel constraints arise only in particular defence, government, export-control, procurement, or contractual contexts (e.g. US-persons/US-soil arrangements for federal workloads, GovCloud). FedRAMP itself is a federal cloud-security assessment and authorization framework, NOT a universal US-soil or US-persons localization requirement.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T2",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.dlapiperdataprotection.com/index.html?t=law&c=US",
      "notes": "General 'no localization' rests on DLA Piper (T2, 31 Mar 2026). The sectoral-government characterisation rests on the existence of GovCloud, not on FedRAMP policy text read this pass."
    },
    {
      "id": "CN-DP",
      "jurisdiction": "China",
      "dimension": "data_protection",
      "instrument": "Three-pillar framework: Cybersecurity Law (CSL), Data Security Law (DSL), Personal Information Protection Law (PIPL)",
      "article_section": "PIPL (2021); DSL (2021); CSL (2017, amended in force 2026-01-01); CSL Art. 61¶3 / Art. 69¶2 (penalties)",
      "status": "in force",
      "provision": "PIPL operative since 1 Nov 2021; DSL since 1 Sep 2021; CSL since 1 Jun 2017 with its first amendment in force 1 Jan 2026 (removes the prior 'warning first' step before fines, broadens extraterritorial enforcement to any overseas activity harming China's cybersecurity, and adds new Art. 20 on AI governance). Supervision led by the Cyberspace Administration of China (CAC) with concurrent MPS/MIIT/SAMR competences; no single independent DPA.",
      "dates": {
        "enacted": "CSL amendment passed NPCSC 2025-10-28",
        "in_force": "PIPL 2021-11-01; DSL 2021-09-01; CSL 2017-06-01; CSL amendment 2026-01-01",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm",
      "notes": "CSL penalties verified against the consolidated amended text (CAC republication, read 28 Aug 2026, print on file): specified fixed-amount penalties under Arts. 61(3) and 69(2) reach RMB 10,000,000; other CSL penalties are calculated by reference to unlawful income (Art. 63) or procurement amounts (Art. 67). The CSL does not use a turnover-percentage penalty. PIPL Art. 66's ceiling (up to CNY 50m or 5% of prior-year turnover) is PIPL's own and must never be attributed to the CSL."
    },
    {
      "id": "CN-AI",
      "jurisdiction": "China",
      "dimension": "ai_regulation",
      "instrument": "Stacked binding CAC administrative measures (no omnibus AI statute)",
      "article_section": "Algorithmic Recommendation Provisions; Deep Synthesis Provisions; Generative AI Interim Measures; AI Content Labelling Measures + GB 45438-2025; Anthropomorphic AI Interaction Interim Measures (CAC Order No. 21)",
      "status": "in force",
      "provision": "No omnibus AI statute. Instead a stack of binding, service-specific CAC-led measures, each in force on a single commencement date: Algorithmic Recommendation (2022-03-01), Deep Synthesis (2023-01-10), Generative AI Interim Measures (2023-08-15), AI-Generated Content Labelling Measures + mandatory standard GB 45438-2025 (2025-09-01), and Anthropomorphic AI Interaction Services Interim Measures (2026-07-15). Control mechanism: for generative-AI services with public-opinion attributes or social-mobilization capability, Art. 17 of the Generative AI Interim Measures requires both security assessment and algorithm filing - a licensing-adjacent gate for those services, not a universal requirement for every generative-AI service, and not EU-style risk-tiering.",
      "dates": {
        "enacted": "",
        "in_force": "2022-03-01; 2023-01-10; 2023-08-15; 2025-09-01; 2026-07-15 (each instrument)",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
      "notes": "Effective-date clauses read in the original Chinese (verbatim in corpus: e.g. Anthropomorphic Interaction Measures Art. 32 '本办法自2026年7月15日起施行'). Negative claim (no comprehensive statute) sourced to NPC Observer (2026-05-11); note an unresolved framing conflict — some outlets report a State Council 'comprehensive AI law' in preparation, but no instrument has entered passage, so status of any comprehensive statute is best expressed as none/at-research-stage, never in requirement language."
    },
    {
      "id": "CN-XBORDER",
      "jurisdiction": "China",
      "dimension": "cross_border_transfer",
      "instrument": "Authorisation- and threshold-based outbound-data regime (CAC)",
      "article_section": "PIPL cross-border chapter; 2024 Cross-border Data Flow Provisions; Certification Measures (CAC/SAMR, in force 2026-01-01)",
      "status": "in force",
      "provision": "China uses an authorisation- and threshold-based outbound-data regime. Depending on the data, processor, and annual export volume, compliance may require a CAC security assessment, personal-information-protection certification, a filed standard contract, compliance with an applicable treaty or agreement, or another condition prescribed by the CAC. The 2024 thresholds are based principally on cumulative exports during the relevant annual period, not on the total population a processor handles: a CIIO exporting personal information or important data must undertake security assessment; a non-CIIO must do so when exporting important data, non-sensitive personal information of >=1,000,000 individuals, or sensitive personal information of >=10,000 individuals. The intermediate band (100,000 to fewer than 1,000,000 individuals' non-sensitive personal information, with the separate <10,000-individuals sensitive-PI threshold, and subject to the 2024 Provisions' exemptions) generally falls to the standard-contract or certification routes.",
      "dates": {
        "enacted": "Certification Measures issued 2025-10-17",
        "in_force": "Certification route 2026-01-01; 2024 Provisions 2024-03-22",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.loc.gov/item/global-legal-monitor/2026-02-19/china-certification-measures-issued-for-cross-border-transfers-of-personal-data/",
      "notes": "Sourced to Library of Congress Global Legal Monitor (T1) plus corpus T2 corroboration. The 2024 Provisions selectively loosened thresholds; the substantive supervisory gate remains CAC-controlled across all three routes."
    },
    {
      "id": "CN-LOCAL",
      "jurisdiction": "China",
      "dimension": "data_localization",
      "instrument": "PIPL Art. 40 + Network Data Security Management Regulation",
      "article_section": "PIPL Art. 40; Network Data Security Management Regulation (in force 2025-01-01)",
      "status": "in force",
      "provision": "Broad in effect though formally sectoral/threshold-based. PIPL Art. 40 requires CIIOs, and PI handlers processing volumes above CAC thresholds, to store personal information collected or generated in China within mainland China, with export conditional on a CAC security assessment. Important-data localization arises separately - from the CSL, the DSL, and the Network Data Security Management Regulation (in force 1 Jan 2025) - not from PIPL Art. 40.",
      "dates": {
        "enacted": "",
        "in_force": "PIPL 2021-11-01; Network Data Security Management Regulation 2025-01-01",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T2",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/asia-pacific/china/topics/data-localization-and-regulation-of-non-personal-data",
      "notes": "Characterisation sourced T2 (Baker McKenzie, DLA Piper, Morgan Lewis). The PIPL Art. 40 mechanism is well established; the T2 tier reflects that the specific threshold mechanics were read off trackers rather than the statute this pass."
    },
    {
      "id": "CA-DP",
      "jurisdiction": "Canada",
      "dimension": "data_protection",
      "instrument": "Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5",
      "article_section": "PIPEDA s. 4 (application); s. 28 (penalties); s. 16 (remedies)",
      "status": "in force",
      "provision": "PIPEDA applies to organisations handling personal information in the course of commercial activities. Enforcement by the Office of the Privacy Commissioner (ombuds model). Penalties: summary-conviction fine up to CAD 10,000; indictable offence up to CAD 100,000 (s. 28). No administrative monetary penalty regime.",
      "dates": {
        "enacted": "2000",
        "in_force": "Consolidation current to 2026-05-26; last amended 2025-03-04",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html",
      "notes": "Read from the Justice Laws consolidated text (T0). ANTI-IMPORT GUARD: the CAD 10,000,000 / 3%-of-global-revenue ceiling belongs to the PROPOSED Bill C-36, not to PIPEDA — never attach it to PIPEDA. A PIPEDA data-mobility amendment (Division 1.2, added by Bill C-15, Royal Assent 2026-03-26) is ENACTED-NOT-IN-FORCE — the consolidated Act current to 2026-05-26 contains no Division 1.2. Quebec (P-39.1), Alberta (PIPA) and BC (PIPA) operate substantially-similar provincial regimes but were not verified on primary text this pass."
    },
    {
      "id": "CA-AI",
      "jurisdiction": "Canada",
      "dimension": "ai_regulation",
      "instrument": "No comprehensive federal AI statute; AIDA withdrawn; Ontario ESA AI hiring disclosure; Bill C-36 proposed",
      "article_section": "Bill C-27 (AIDA — died); Ontario ESA 2000 (job-posting disclosure); Bill C-36",
      "status": "withdrawn",
      "provision": "No comprehensive federal AI statute. The Artificial Intelligence and Data Act (AIDA), carried in Bill C-27, died on the Order Paper when the 44th Parliament's 1st session ended 6 Jan 2025 and was never enacted. Binding provincial sectoral duties nevertheless exist: Ontario's job-posting AI-disclosure requirement applies to covered publicly advertised postings by employers with 25 or more employees and has been in effect since 1 Jan 2026. Bill C-36 is principally federal privacy reform and should NOT be presented as a replacement comprehensive AI bill.",
      "dates": {
        "enacted": "",
        "in_force": "Ontario AI hiring disclosure 2026-01-01",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.parl.ca/legisinfo/en/bill/44-1/c-27",
      "secondary_urls": [
        "https://www.ontario.ca/laws/regulation/r24476"
      ],
      "notes": "AIDA status (died on the Order Paper, never enacted) per LEGISinfo (T0); it has no entry-into-force date and is never described as a requirement. Ontario job-posting AI-disclosure duty primary-verified: O. Reg. 476/24 under the ESA (ontario.ca), applying from 1 Jan 2026 to employers with 25 or more employees. Bill C-36 is principally federal privacy reform, not a replacement AI bill. Quebec P-39.1 s. 12.1 (automated decisions) is likely Canada's most substantive in-force AI-adjacent right but was not verified (sources unreachable) - see gaps."
    },
    {
      "id": "CA-XBORDER",
      "jurisdiction": "Canada",
      "dimension": "cross_border_transfer",
      "instrument": "PIPEDA accountability-based transfer model; inbound partial EU adequacy",
      "article_section": "PIPEDA (accountability principle); OPC cross-border guidelines",
      "status": "in force",
      "provision": "Permissive-default, accountability-based: PIPEDA does not prohibit transborder transfers and requires no adequacy assessment; per OPC guidance, no additional consent is required where personal information is transferred to a service provider for processing on the organization's behalf for the original purpose - the OPC distinguishes such transfers from disclosures, and its conclusion is not a blanket rule for every international disclosure. The transferring organization remains accountable and uses contracts to require 'generally equivalent' protection. Inbound from the EU rests on Canada's partial EU adequacy decision (limited to PIPEDA-covered commercial organizations).",
      "dates": {
        "enacted": "",
        "in_force": "OPC guidelines 2009-01-27; EU adequacy in force",
        "rules_effective": "",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.priv.gc.ca/en/privacy-topics/personal-information-transferred-across-borders/gl_dab_090127/",
      "notes": "Domestic mechanism from OPC guidelines (T1). Inbound EU adequacy live-confirmed on the Commission adequacy page (2026-07-23): 'Canada (commercial organisations).' Adequacy does not extend to Canadian government bodies or non-PIPEDA organisations. The underlying Commission decision text was not read this pass; the fact of listing is verified."
    },
    {
      "id": "CA-LOCAL",
      "jurisdiction": "Canada",
      "dimension": "data_localization",
      "instrument": "No federal private-sector localization mandate",
      "article_section": "n/a",
      "status": "in force",
      "provision": "No data-localization requirement at the federal private-sector level. Canada treats traditional localization as generally ineffective and is instead exploring risk-based transfer assessments and targeted sectoral approaches.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T2",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.osler.com/en/insights/reports/2025-legal-outlook/canadas-2026-privacy-priorities-data-sovereignty-open-banking-and-ai/",
      "notes": "Scoped to the FEDERAL PRIVATE SECTOR. Sourced negative (Osler, T2, 2025-12-04). Provincial public-sector statutes (notably BC and Nova Scotia) have historically carried in-province storage rules; whether any survive was not verified — do not extend the negative beyond the federal private sector."
    },
    {
      "id": "BR-DP",
      "jurisdiction": "Brazil",
      "dimension": "data_protection",
      "instrument": "Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709/2018",
      "article_section": "LGPD Art. 3 (territorial scope); Arts. 52-54 (sanctions)",
      "status": "in force",
      "provision": "LGPD is in force. Territorial scope (Art. 3) has THREE limbs: (I) processing carried out in national territory; (II) processing whose purpose is offering/supplying goods or services to, or processing data of, individuals located in Brazil; (III) personal data collected in Brazil. Supervisory authority is the ANPD, upgraded to a full regulatory agency by Lei nº 15.352/2026.",
      "dates": {
        "enacted": "2018-08-14 (published DOU 2018-08-15)",
        "in_force": "2020-09-18 (substantive law)",
        "rules_effective": "2021-08-01 (administrative sanctions Arts. 52-54 enforceable)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm",
      "notes": "Instrument (T0 Planalto/LexML) and corrected Art. 3 text are primary-verified. Entry-into-force (18 Sep 2020) and sanctions-application (1 Aug 2021) dates rest on T2 (DLA Piper) plus the visible amending chain (MP 869/2018, Lei 13.853/2019, MP 959/2020, Lei 14.010/2020) — confidence capped where the operative Art. 65 text was not read. ANPD agency-conversion date (Lei 15.352/2026) is T4 press-service sourced."
    },
    {
      "id": "BR-AI",
      "jurisdiction": "Brazil",
      "dimension": "ai_regulation",
      "instrument": "PL nº 2338/2023 (Marco Legal da Inteligência Artificial)",
      "article_section": "n/a (bill)",
      "status": "proposed",
      "provision": "No comprehensive AI statute in force. PL 2338/2023 — a risk-tiered bill (excessive/high/non-high risk) modelled on the EU AI Act — was approved by the Federal Senate plenary on 10 Dec 2024 and transmitted to the Chamber of Deputies on 17 Mar 2025, where it remains before a Special Commission awaiting the rapporteur's opinion (latest tramitação 17 Jun 2026). Because it is proposed it imposes, mandates and prohibits nothing. The ANPD has issued no binding AI-specific normative act.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.camara.leg.br/proposicoesWeb/fichadetramitacao?idProposicao=2487262",
      "notes": "Status verified on the Câmara tramitação record (T0). PL 2338 penalty ceilings reported in secondary sources (R$50m / 2% of revenue) must NEVER be published as operative and must not be imported into any LGPD penalty field. Do not publish any predicted floor-vote date — all have slipped."
    },
    {
      "id": "BR-XBORDER",
      "jurisdiction": "Brazil",
      "dimension": "cross_border_transfer",
      "instrument": "LGPD Chapter V + Resolução CD/ANPD nº 19/2024; EU-Brazil mutual adequacy",
      "article_section": "LGPD Arts. 33-36; Resolução 19/2024; Commission Implementing Decision (EU) 2026/179; Resolução CD/ANPD nº 32/2026",
      "status": "in force",
      "provision": "LGPD Arts. 33-36, implemented by Resolução CD/ANPD nº 19/2024, operationalize five transfer mechanisms (adequacy; ANPD standard contractual clauses; equivalent foreign clauses; specific clauses with prior ANPD approval; global corporate rules) - not an exhaustive statement of LGPD Art. 33, which also includes grounds such as international legal cooperation, protection of life or physical safety, ANPD authorization, public-policy grounds, and specific consent. EU-Brazil mutual adequacy: Commission Implementing Decision (EU) 2026/179, adopted 26 Jan 2026, published OJ L 28 Jan 2026 (ANPD Resolução nº 32/2026 recognizing the EU) - Brazil is now inside a reciprocal free-flow area with the EU.",
      "dates": {
        "enacted": "Resolução 19/2024 published 2024-08-23; EU adequacy adopted 2026-01-26",
        "in_force": "SCC adaptation grace period ended 2024-08-23 + 12 months = 2025-08-23",
        "rules_effective": "",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
      "notes": "Decision (EU) 2026/179 read from the OJ text (EUR-Lex retrieval 28 Aug 2026, on file): adopted 26 Jan 2026, published OJ L 28 Jan 2026; no sunset clause - continuous monitoring under its Art. 3; addressed to Member States (Art. 4). SCC 12-month adaptation deadline (23 Aug 2025) remains T2 (Mayer Brown)."
    },
    {
      "id": "BR-LOCAL",
      "jurisdiction": "Brazil",
      "dimension": "data_localization",
      "instrument": "No general localization mandate (transfer-regime model)",
      "article_section": "LGPD Chapter V (Arts. 33-36)",
      "status": "in force",
      "provision": "No broad/general personal-data localization mandate. Brazil regulates outbound flows through the LGPD Chapter V transfer-mechanism regime rather than by requiring in-country storage.",
      "dates": {
        "enacted": "",
        "in_force": "",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T1",
      "confidence": "MEDIUM",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.gov.br/anpd/pt-br/assuntos/assuntos-internacionais/transferencia-internacional-de-dados",
      "notes": "General 'no localization' finding covers the general regime only. Sector overlays (notably Banco Central cloud/outsourcing rules) were not verified — do not present this as covering financial-sector residency."
    },
    {
      "id": "IN-DP",
      "jurisdiction": "India",
      "dimension": "data_protection",
      "instrument": "Digital Personal Data Protection Act, 2023 (No. 22 of 2023) + DPDP Rules, 2025 (G.S.R. 846(E))",
      "article_section": "DPDP Act s.1(2) (commencement), s.3 (extraterritorial scope), Schedule (penalties); DPDP Rules 2025 rule 1(2)-(4)",
      "status": "in force",
      "provision": "The Act received assent 11 Aug 2023 but commences section-by-section by notification (s.1(2)); it had no operative provisions on assent. The DPDP Rules 2025 phase in: rules 1, 2, 17-21 on gazette publication (13/14 Nov 2025); rule 4 (Consent Managers) one year later (~13/14 Nov 2026); rules 3, 5-16, 22, 23 (notice, consent, security, breach notification, children's data, SDF duties, data-principal rights, cross-border transfer) eighteen months later (~13/14 May 2027). Institutional and implementation provisions are live; the substantive compliance core - data-fiduciary obligations, rights, transfers, and the principal penalties - is enacted but not in force until the eighteen-month tranche commences. Extraterritorial (s.3(b)). Penalties (Schedule) up to ₹250 crore (s.8(5) security-safeguard breach) - enacted but not operational until that tranche.",
      "dates": {
        "enacted": "2023-08-11 (assent)",
        "in_force": "Rules phase I on gazette publication (13/14 Nov 2025)",
        "rules_effective": "Consent Manager tranche ~13/14 Nov 2026; substantive core ~13/14 May 2027 (enacted-not-in-force)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
      "notes": "Act and Rules read verbatim from gazette texts (T0; gazettes on file, retrieved 28 Aug 2026). The G.S.R. 843(E) gazette carries both candidate dates itself - notified 13 Nov 2025; digitally signed / e-published 14 Nov 2025 10:37 IST - and the commencement clauses key to the date of publication; downstream phase dates are published as 13/14 ranges until the controlling date is determined. Assent (11 Aug 2023) is not entry into force. Penalty ceilings belong to the DPDP Act Schedule and are not attributed to the IT Act 2000. Interim regime is IT Act 2000 + 2011 Rules until the substantive tranche commences."
    },
    {
      "id": "IN-AI",
      "jurisdiction": "India",
      "dimension": "ai_regulation",
      "instrument": "No comprehensive AI statute; India AI Governance Guidelines (soft-law) + binding synthetic-media rules in IT Rules 2021",
      "article_section": "India AI Governance Guidelines (MeitY, non-binding); IT (Intermediary Guidelines) Rules 2021 rr. 2(1)(wa), 3(3) (inserted by G.S.R. 120(E), 10 Feb 2026)",
      "status": "in force",
      "provision": "No comprehensive, cross-sector AI statute; MeitY's framework places new AI laws in the long-term column; its voluntary measures are 'not legally binding.' The India AI Governance Guidelines (seven 'sutras') are soft law. But binding synthetic-media obligations exist at the intermediary layer: IT Rules 2021 r. 3(3), inserted by G.S.R. 120(E) dated 10 February 2026, requires covered intermediaries to deploy reasonable and appropriate technical measures against unlawful SGI and to prominently label other covered SGI and, to the extent technically feasible, embed permanent metadata or another appropriate technical provenance mechanism.",
      "dates": {
        "enacted": "SGI amendment notified G.S.R. 120(E) 2026-02-10",
        "in_force": "IT Rules 2021 SGI provisions (notified 2026-02-10; reported in force 2026-02-20)",
        "rules_effective": "",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf",
      "notes": "Negative claim (no comprehensive AI statute) and the SGI rule text are primary-verified (MeitY, T0). Amending-instrument date caution: notification (10 Feb 2026) is T0; the reported 20 Feb 2026 in-force date rests on a single legal-directory article (Chambers) and is NOT one of the named tier-1 trackers — treat the 10-day gap as unconfirmed and publish notification date as the solid anchor."
    },
    {
      "id": "IN-XBORDER",
      "jurisdiction": "India",
      "dimension": "cross_border_transfer",
      "instrument": "DPDP Act s.16 + DPDP Rule 15 (permissive-default / blacklist)",
      "article_section": "DPDP Act s.16(1)-(2); DPDP Rules 2025 rule 15",
      "status": "enacted-not-in-force",
      "provision": "DPDP Act s.16 and DPDP Rule 15 are enacted but NOT yet in force. Both form part of the substantive eighteen-month tranche expected to commence approximately 13/14 May 2027, subject to the controlling Official Gazette publication date. Until commencement, India's DPDP negative-list transfer mechanism is not operative law. The model, once live, is permissive-default (negative list) rather than adequacy or SCC based: DPDP s.16(1) allows the Central Government to restrict transfer to notified countries.",
      "dates": {
        "enacted": "s.16 enacted with the Act (assent 11 Aug 2023); Rule 15 made with the Rules (gazette 13/14 Nov 2025)",
        "in_force": "",
        "rules_effective": "s.16 + Rule 15 commence with the substantive tranche ~13/14 May 2027 (enacted-not-in-force)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://egazette.gov.in",
      "secondary_urls": [
        "https://www.indiacode.nic.in/handle/123456789/2029"
      ],
      "notes": "s.16 and Rule 15 read verbatim from gazette texts (T0). No restricted-country notification located — but the absence is not affirmatively sourced, so do not state 'no country is blacklisted' as a finding; state only that none was located. Source: G.S.R. 843(E), Gazette of India Extraordinary, Pt. II §3(i), serial 7592 - retrieved from egazette.gov.in 28 Aug 2026, on file at _sources/india-research-package-2026-08-28/egazette/."
    },
    {
      "id": "IN-LOCAL",
      "jurisdiction": "India",
      "dimension": "data_localization",
      "instrument": "Sectoral: RBI payments-data directive; CERT-In log-retention directions; prospective DPDP Rule 13(4)",
      "article_section": "RBI DPSS.CO.OD No.2785 (2018); CERT-In Directions No. 20(3)/2022 dir. (iv); DPDP Rules 2025 rule 13(4)",
      "status": "in force",
      "provision": "Sectoral localization, no economy-wide personal-data mandate. (1) PAYMENTS: RBI directive of 6 Apr 2018 — 'the entire data relating to payment systems ... stored in a system only in India.' (2) CYBERSECURITY LOGS: CERT-In directions (28 Apr 2022) require ICT system logs to be maintained for a rolling 180 days 'within the Indian jurisdiction.' (3) PROSPECTIVE: DPDP Rule 13(4) will let the Central Government bar specified Significant-Data-Fiduciary data from leaving India — but Rule 13 is in the 18-month tranche (effective ~13 May 2027) with no specifying notification yet.",
      "dates": {
        "enacted": "RBI 2018-04-06; CERT-In 2022-04-28",
        "in_force": "RBI directive 2018; CERT-In directions effective ~late June 2022 (60 days after issue)",
        "rules_effective": "DPDP Rule 13(4) ~13 May 2027 (enacted-not-in-force)",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244&Mode=0",
      "notes": "RBI, CERT-In and DPDP Rule 13(4) texts read verbatim (T0). CERT-In four-date discipline: issue date (28 Apr 2022) differs from effective date (60 days later)."
    },
    {
      "id": "KR-DP",
      "jurisdiction": "South Korea",
      "dimension": "data_protection",
      "instrument": "Personal Information Protection Act (PIPA), as amended 2026",
      "article_section": "PIPA Art. 64-2 (penalties, incl. new (2) tier); 2026 amendment (promulgated 2026-03-10)",
      "status": "in force",
      "provision": "Base PIPA in force; a 2026 amendment (promulgated 10 Mar 2026, applies from 11 Sep 2026, with mandatory ISMS-P certification deferred to 1 Jul 2027) adds an aggravated penalty tier of up to 10% of total turnover (Art. 64-2(2)) atop the existing 3% tier - both computed on total turnover subject to the statutory turnover-calculation and deduction rules (revenue unrelated to the violation excluded) - plus express representative-director (CEO) accountability. Enforced by the Personal Information Protection Commission (PIPC).",
      "dates": {
        "enacted": "2026 amendment passed 2026-02-12; promulgated 2026-03-10",
        "in_force": "Base PIPA in force",
        "rules_effective": "2026 amendment applies from 2026-09-11 (enacted-not-in-force until then); ISMS-P limb 2027-07-01",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://www.law.go.kr/법령/개인정보보호법",
      "secondary_urls": [
        "https://www.dlapiperdataprotection.com/index.html?t=law&c=KR",
        "https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS212&mCode=C040030000&nttId=11944"
      ],
      "notes": "Art. 64-2 penalty structure verified against the Korean statutory text (official law.go.kr PDF retrieved 28 Aug 2026, on file): current 3%-of-total base with the unrelated-revenue deduction; aggravated up-to-10%-of-total tier inserted 2026-03-10, effective 2026-09-11, with the calculation provisions extended to it. Four-date discipline: promulgation (10 Mar 2026) is not application (11 Sep 2026). PIPA penalty ceilings belong to PIPA and are not conflated with the AI Framework Act's KRW 30m administrative fines."
    },
    {
      "id": "KR-AI",
      "jurisdiction": "South Korea",
      "dimension": "ai_regulation",
      "instrument": "Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act), Act No. 20676",
      "article_section": "Addenda (부칙) Art. 1 (commencement); Arts. 30-35 (core obligations); extraterritorial-scope + domestic-representative provisions",
      "status": "in force",
      "provision": "A comprehensive, risk-tiered AI statute - alongside the EU AI Act, one of the comprehensive horizontal AI regimes examined in this brief. In force since 22 Jan 2026 (one year after promulgation on 21 Jan 2025), together with its Enforcement Decree. Risk model: 'high-impact AI' (healthcare, hiring, biometrics, etc.), generative-AI transparency/labeling, and 'high-performance AI' - triggered only where three conditions hold together: training compute exceeding 10^26 FLOPs, state-of-the-art technology, and a risk of broad and significant effects on fundamental rights. Extraterritorial reach over foreign operators affecting Korean users/markets, with a domestic-representative duty above defined thresholds. Administrative fines up to KRW 30 million.",
      "dates": {
        "enacted": "Passed National Assembly 2024-12-26; promulgated 2025-01-21",
        "in_force": "2026-01-22",
        "rules_effective": "Digital-medical-device limb 2026-01-24; further deferred provisions (Act No. 21311 Addendum) 2026-07-21",
        "as_of_access": "2026-07-20"
      },
      "source_tier": "T1",
      "confidence": "HIGH",
      "last_verified": "2026-08-27",
      "primary_url": "https://www.law.go.kr/lsInfoP.do?lsiSeq=268543",
      "notes": "In-force date (22 Jan 2026) confirmed by MSIT + US ITA + Cooley + Littler + Chambers (five independent sources). One divergence: KLRI's English translation page renders the enforcement date as 21 Jan 2026 — recorded but outweighed 5-to-1 and consistent with the '공포 후 1년이 경과한 날' (one year after promulgation) convention. MSIT is operating a >=1-year enforcement grace period through 2026 (forbearance, not suspension — obligations are legally live). Article numbers and the KRW 30m ceiling are T1/T2-attributed, not verified against the Korean text (law.go.kr 502). Corpus correction noted: the deferred-commencement surface is larger than first recorded (Act No. 21311 Addendum defers several amended provisions to 2026-07-21) — core in-force status unaffected."
    },
    {
      "id": "KR-XBORDER",
      "jurisdiction": "South Korea",
      "dimension": "cross_border_transfer",
      "instrument": "PIPA outbound-transfer regime (consent + adequacy + certification + statutory grounds)",
      "article_section": "PIPA cross-border provisions; PIPC adequacy recognition (2025-09-03)",
      "status": "in force",
      "provision": "Outbound transfer is permitted on several statutory grounds: (i) separate specific consent; (ii) PIPC recognition of the destination as ensuring an equivalent level of protection (adequacy); (iii) PIPC-recognized certification (ISMS-P); and (iv) transfers grounded in law, in a treaty or international convention, or in certain contract-performance or storage arrangements - consent is one route, not the default. PIPC issued its first adequacy recognition - covering the EU/EEA - on 3 Sep 2025. Korea also holds inbound EU adequacy. SCCs and BCRs are only proposed under Korean law and are not yet available mechanisms.",
      "dates": {
        "enacted": "",
        "in_force": "PIPC EU adequacy recognition 2025-09-03",
        "rules_effective": "",
        "as_of_access": "2026-07-23"
      },
      "source_tier": "T0",
      "confidence": "HIGH",
      "last_verified": "2026-08-28",
      "primary_url": "https://www.law.go.kr/법령/개인정보보호법",
      "secondary_urls": [
        "https://www.dlapiperdataprotection.com/index.html?t=law&c=KR",
        "https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS212&mCode=C040030000&nttId=11944"
      ],
      "notes": "Transfer grounds read from the official law.go.kr PIPA text (retrieved 28 Aug 2026, on file). Korea's inbound EU adequacy live-confirmed on the Commission adequacy page (2026-07-23). SCC/BCR remain an announced PIPC intention only - not available mechanisms."
    }
  ],
  "published_gaps": [
    {
      "id": "EU-LOCAL",
      "jurisdiction": "European Union",
      "dimension": "data_localization",
      "status": "published gap",
      "last_verified": "2026-08-27",
      "reason": "declined to source a 'none' - published as a gap, not a clean negative"
    },
    {
      "id": "KR-LOCAL",
      "jurisdiction": "South Korea",
      "dimension": "data_localization",
      "status": "published gap",
      "last_verified": "2026-08-27",
      "reason": "sector position unverified - published as a gap"
    }
  ]
}