Personal data follows ordinary business activity. A customer completes a form, an employee sends a spreadsheet to a pension adviser, a supplier uploads identification records, or a project team shares documents containing names and contact details.
Data privacy determines how that information may be collected, used, shared, retained and deleted. The legal detail changes between jurisdictions, but the practical expectation is consistent: organisations should know what personal information they hold, why they need it and who can access it.
Customers, suppliers, cloud providers and professional advisers can place one business process under several privacy regimes.
GDPR
GDPR
Good privacy practice begins before a file is shared
Privacy is often discussed after an incident, yet most of the important decisions happen earlier. The organisation chooses what to collect, how clearly to explain the purpose, where to store the information and which employees or external parties need access.
Poor control creates practical problems. Records are duplicated, retention periods become unclear and subject access requests take longer because nobody has a reliable picture of where the information sits. Customers may also lose confidence when a business cannot explain why their data was shared.
Privacy also has a commercial dimension. Accurate data supports better service, controlled access reduces unnecessary exposure, and a clear exchange process makes it easier to work with security-conscious customers and supply-chain partners.
The EU GDPR sets the benchmark for modern privacy law
The General Data Protection Regulation applies across the European Union and can also reach organisations elsewhere when they offer goods or services to people in the EU or monitor their behaviour. The official GDPR text on EUR-Lex sets out obligations for controllers and processors alongside enforceable rights for individuals.
Seven principles guide the full processing lifecycle
The GDPR requires organisations to consider purpose, necessity, accuracy, retention, security and accountability rather than treating privacy as a final approval step.
Individuals may have rights to access, correct, erase or move their information, object to certain processing and request restrictions. These rights are not absolute in every circumstance, so organisations need a documented process for assessing each request.
The GDPR also expects appropriate technical and organisational measures. Encryption, access control and activity records may contribute, but compliance depends on lawful processing, contracts, retention, staff behaviour and wider governance. Our guide to GDPR-focused file sharing explains how exchange controls can support that broader responsibility.
Privacy obligations change as information crosses borders
There is no single global privacy law. Definitions, thresholds, lawful bases, consumer rights and enforcement models vary. The examples below are useful reference points, but they are not a substitute for checking the rules that apply to a specific organisation and processing activity.
Regulatory atlas
Select a jurisdiction for a concise view of its current framework.
UK GDPR and the Data Protection Act 2018
The UK retained a domestic version of the GDPR after leaving the EU. It operates alongside the Data Protection Act 2018 and has been amended by the Data (Use and Access) Act 2025.
All data-protection provisions of the 2025 Act were in force by 19 June 2026. Organisations should use the ICO's current DUAA guidance when reviewing UK processes.
California Consumer Privacy Act
The CCPA, as amended by the California Privacy Rights Act, gives eligible California consumers rights over personal information collected by covered businesses.
These can include rights to know, delete and correct information, to opt out of sale or sharing, and to limit certain uses of sensitive personal information. The California Privacy Protection Agency's guidance explains the current rights and responsibilities.
Canada's federal private-sector framework
PIPEDA sets ground rules for how many private-sector organisations collect, use and disclose personal information during commercial activity.
Its ten fair information principles cover accountability, consent, limited collection, safeguards, openness and individual access. Provincial legislation can also apply. The Office of the Privacy Commissioner of Canada provides current business guidance.
Brazil's General Data Protection Law
The LGPD governs the processing of personal data and protects rights connected with freedom, privacy and personal development.
It includes processing principles, legal bases, individual rights and requirements around international transfers and security incidents. Brazil's National Data Protection Authority provides an official English version of the LGPD.
Australian Privacy Act and APPs
Australia's Privacy Act includes 13 Australian Privacy Principles for covered organisations and agencies.
The principles address collection, use, disclosure, governance, accuracy, access and security. Applicability depends on the organisation and activity. The Office of the Australian Information Commissioner maintains current guidance on the APPs.
Cross-border sharing needs a defined legal and operational route
A transfer may occur when information is sent to an overseas customer, accessed by a support team in another country or stored with a provider using international infrastructure. The organisation needs to understand the locations involved and the safeguards required by the relevant law.
Data residency and data sovereignty are related but distinct. Residency concerns where data is stored. Sovereignty concerns the laws and authorities that may apply to it. Contracts, technical architecture and actual access locations should be reviewed together.
A privacy programme should answer ordinary operational questions
The exchange itself deserves particular attention. Email attachments and unrestricted public links can make it harder to control recipients, availability and evidence. A controlled B2B file-exchange process helps define the handoff when personal information moves between organisations.
How My MX Data contributes to stronger information handling
My MX Data is a secure B2B file-exchange platform. MX helps organisations direct files to approved or named recipients, apply multi-factor authentication and define how long access remains available.
AES-256 encryption forms part of the wider security model. Detailed transaction records can show uploads, access, downloads, comments and recipient activity, helping administrators review what happened during an exchange. Relevant configurations may also support data-location requirements, secure upload portals and enterprise identity controls.
These features can support privacy and compliance objectives by reducing uncertainty around external transfers. They do not establish the legal basis for processing, decide retention policy or replace staff training, contracts and legal assessment.
Jurisdiction, sector, business size, data type, processing purpose and contractual relationships can all affect the legal position. Organisations should verify current regulator guidance and obtain specialist advice where the risk or complexity justifies it.
Data privacy becomes more manageable when the organisation can trace the information from collection to deletion. The law may differ by country, but disciplined handling, restrained access and clear evidence remain useful wherever the file travels.