Global Privacy & Regional Rights
Privacy rights and data-protection information for the markets where AttributionPath™ is used.
Effective 24 August 2026. AttributionPath™ is used across markets with different privacy regimes. This page explains the principal regional privacy frameworks and rights that may apply when AttributionPath™ is used. The requirements that apply in a particular case depend on factors including location, the parties’ data-protection roles, the service configuration and the nature of the processing.
European Union / EEA — GDPR
Where Regulation (EU) 2016/679 applies, the framework includes controller/processor role allocation, lawful basis, transparency, data-subject rights, data minimisation, security, processor contracts under Article 28, breach obligations and Chapter V transfer mechanisms. Customers remain responsible for the lawful basis and notices for their own deployment.
United Kingdom — UK GDPR and Data Protection Act
UK processing is handled with the UK controller/processor framework, Article 28-style processor commitments and UK restricted-transfer rules. Where appropriate safeguards are required, the UK IDTA or UK Addendum and transfer-risk assessment process may be used.
California — CCPA / CPRA
Where the California Consumer Privacy Act, as amended by the CPRA, applies, covered consumers may have rights concerning access/knowledge, deletion, correction, portability, sale/sharing opt-out and certain sensitive-information uses. Where AttributionPath™ acts as a service provider or contractor, processing is restricted to the permitted business purposes and contractual instructions.
Other United States state privacy laws
US state privacy laws increasingly provide access, deletion, correction, portability, opt-out and appeal rights, with varying definitions, thresholds and exemptions. AttributionPath™ uses a role-based processor/service-provider model intended to support customer compliance where those laws apply. A customer must determine the specific state law, threshold and opt-out requirements relevant to its business.
Canada — PIPEDA and provincial laws
Where PIPEDA applies, the framework addresses accountability, identified purposes, consent, limited collection/use/retention, safeguards, openness, individual access and challenge mechanisms. Provincial private-sector privacy laws may apply instead of or alongside PIPEDA in particular circumstances.
Brazil — LGPD
Where Brazil's Lei Geral de Proteção de Dados applies, processing should be tied to a lawful legal basis, transparency, purpose limitation, data-subject rights, security, incident obligations and applicable international-transfer requirements. Controller/operator responsibilities are allocated by the actual processing relationship.
Australia — Privacy Act and Australian Privacy Principles
Where the Australian Privacy Act and APPs apply, the framework supports transparent privacy management, notice, collection limitation, use/disclosure controls, direct-marketing requirements, cross-border disclosure, security, access and correction. Customers must assess whether they are an APP entity and any exemptions or additional sector rules.
New Zealand — Privacy Act 2020
Where New Zealand law applies, customers should address collection, purpose, notice, security, access/correction, retention, disclosure and overseas-transfer requirements, together with notifiable privacy breach obligations.
Singapore — PDPA
Where Singapore's Personal Data Protection Act applies, organisations should address consent or other permitted bases, purpose limitation, notification, access/correction, protection, retention limitation, transfer limitation and breach notification obligations.
Japan — APPI
Where Japan's Act on the Protection of Personal Information applies, handling of personal information, retained personal data, provision to third parties and cross-border transfers must follow APPI requirements and applicable Personal Information Protection Commission rules and guidance.
South Africa — POPIA
Where the Protection of Personal Information Act applies, processing should meet the conditions for lawful processing, including accountability, processing limitation, purpose specification, further-processing compatibility, information quality, openness, security safeguards and data-subject participation.
Switzerland — Federal Act on Data Protection
Where the Swiss Federal Act on Data Protection applies, the service framework supports transparency, proportionality, security, processor controls, data-subject rights and cross-border transfer requirements applicable to Swiss personal data.
Other jurisdictions
Privacy law continues to develop across Latin America, the Middle East, Africa and Asia-Pacific. AttributionPath™ does not treat this page as a closed list. Where a customer operates in another jurisdiction, the applicable law, customer role, data flow, consent/notice requirements and transfer mechanism should be assessed for that deployment. Contractual or technical controls can then be applied where supported.
A global baseline, local obligations
Our baseline is data minimisation, role clarity, purpose limitation, security, documented processor instructions, rights assistance, retention controls and lawful transfer mechanisms. Local law can require more. The applicable regional rules prevail where they impose additional mandatory obligations.
Privacy contact
Questions about a jurisdiction, rights request or deployment can be sent to privacy@attributionpath.com.