Privacy law follows the customer, not the server: a bookshop in Malaysia that sells to readers in Germany and California answers to three regimes at once.
| Law | In force | Applies to | Maximum penalty |
|---|---|---|---|
| GDPR (EU) | 25 May 2018 | People in the EU | EUR 20M or 4% turnover |
| CCPA/CPRA (California) | 2020; CPRA 2023 | Firms over $26.6M revenue | $7,988 per violation |
| PDPA (Malaysia) | 2013; amended 2024 | Commercial processing | Fine, prison or both |
The GDPR gives rights of access, erasure, portability and objection; its fine is whichever figure is higher. The CCPA gives rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive data; $7,988 applies to intentional violations, $2,663 to others. Malaysia's 2024 amendment came into force during 2025, adding mandatory data protection officers and breach notification from 1 June 2025, and made biometric data sensitive.
For engineers, all three mean the same habits: tag where personal data lives, copy only what a purpose needs (data minimization), enforce retention, and be able to delete one person's records (Retention and GDPR Deletion).