Personal data follows ordinary business activity. A customer completes a form, an employee sends a spreadsheet to a pension adviser, a supplier uploads identification records, or a project team shares documents containing names and contact details.
Data privacy determines how that information may be collected, used, shared, retained and deleted. The legal detail changes between jurisdictions, but the practical expectation is consistent: organisations should know what personal information they hold, why they need it and who can access it.
Customers, suppliers, cloud providers and professional advisers can place one business process under several privacy regimes.
EUGDPR UK
GDPR CCPA LGPD
Good privacy practice begins before a file is shared
Privacy is often discussed after an incident, yet most of the important decisions happen earlier. The organisation chooses what to collect, how clearly to explain the purpose, where to store the information and which employees or external parties need access.
Poor control creates practical problems. Records are duplicated, retention periods become unclear and subject access requests take longer because nobody has a reliable picture of where the information sits. Customers may also lose confidence when a business cannot explain why their data was shared.
CollectDefine the purpose before requesting personal information. UseKeep activity connected to the stated and lawful purpose. ShareConfirm the recipient, authority and necessary data. RetainSet a period based on legal and operational need. DeleteRemove information securely when the purpose has ended.Privacy also has a commercial dimension. Accurate data supports better service, controlled access reduces unnecessary exposure, and a clear exchange process makes it easier to work with security-conscious customers and supply-chain partners.
European UnionA principles-based frameworkThe EU GDPR sets the benchmark for modern privacy law
The General Data Protection Regulation applies across the European Union and can also reach organisations elsewhere when they offer goods or services to people in the EU or monitor their behaviour. The official GDPR text on EUR-Lex sets out obligations for controllers and processors alongside enforceable rights for individuals.
Seven principles guide the full processing lifecycle
The GDPR requires organisations to consider purpose, necessity, accuracy, retention, security and accountability rather than treating privacy as a final approval step.
Lawfulness, fairness and transparency Purpose limitation Data minimisation Accuracy Storage limitation Integrity and confidentiality AccountabilityIndividuals may have rights to access, correct, erase or move their information, object to certain processing and request restrictions. These rights are not absolute in every circumstance, so organisations need a documented process for assessing each request.
The GDPR also expects appropriate technical and organisational measures. Encryption, access control and activity records may contribute, but compliance depends on lawful processing, contracts, retention, staff behaviour and wider governance. Our guide to GDPR-focused file sharing explains how exchange controls can support that broader responsibility.
Global regulationsSimilar aims, different legal routesPrivacy obligations change as information crosses borders
There is no single global privacy law. Definitions, thresholds, lawful bases, consumer rights and enforcement models vary. The examples below are useful reference points, but they are not a substitute for checking the rules that apply to a specific organisation and processing activity.
Regulatory atlas
Select a jurisdiction for a concise view of its current framework.
Official sources linkedUK GDPR and the Data Protection Act 2018
The UK retained a domestic version of the GDPR after leaving the EU. It operates alongside the Data Protection Act 2018 and has been amended by the Data (Use and Access) Act 2025.
All data-protection provisions of the 2025 Act were in force by 19 June 2026. Organisations should use the ICO’s current DUAA guidance when reviewing UK processes.
California Consumer Privacy Act
The CCPA, as amended by the California Privacy Rights Act, gives eligible California consumers rights over personal information collected by covered businesses.
These can include rights to know, delete and correct information, to opt out of sale or sharing, and to limit certain uses of sensitive personal information. The California Privacy Protection Agency’s guidance explains the current rights and responsibilities.
Canada’s federal private-sector framework
PIPEDA sets ground rules for how many private-sector organisations collect, use and disclose personal information during commercial activity.
Its ten fair information principles cover accountability, consent, limited collection, safeguards, openness and individual access. Provincial legislation can also apply. The Office of the Privacy Commissioner of Canada provides current business guidance.
Brazil’s General Data Protection Law
The LGPD governs the processing of personal data and protects rights connected with freedom, privacy and personal development.
It includes processing principles, legal bases, individual rights and requirements around international transfers and security incidents. Brazil’s National Data Protection Authority provides an official English version of the LGPD.
Australian Privacy Act and APPs
Australia’s Privacy Act includes 13 Australian Privacy Principles for covered organisations and agencies.
The principles address collection, use, disclosure, governance, accuracy, access and security. Applicability depends on the organisation and activity. The Office of the Australian Information Commissioner maintains current guidance on the APPs.
Cross-border sharing needs a defined legal and operational route
A transfer may occur when information is sent to an overseas customer, accessed by a support team in another country or stored with a provider using international infrastructure. The organisation needs to understand the locations involved and the safeguards required by the relevant law.
01 OriginIdentify the governing lawConfirm where the people, organisation and processing activity are located. > 02 PurposeDefine why the transfer is neededSend only the personal information required for the stated task. > 03 SafeguardSelect the transfer routeConsider adequacy, contracts and any supplementary measures required. > 04 EvidenceRetain the decisionDocument the recipient, conditions, activity and review process.Data residency and data sovereignty are related but distinct. Residency concerns where data is stored. Sovereignty concerns the laws and authorities that may apply to it. Contracts, technical architecture and actual access locations should be reviewed together.
Practical governanceTurn legal principles into daily controlsA privacy programme should answer ordinary operational questions
01Map the informationKnow which personal data is held, where it sits and which parties receive it. 02Limit collectionRequest only what the business purpose genuinely requires. 03Control accessUse named accounts, suitable authentication and prompt offboarding. 04Set retentionConnect deletion periods to legal, contractual and operational requirements. 05Review suppliersUnderstand processing roles, locations, security and onward sharing. 06Prepare for incidentsDefine how suspected loss, misuse or unauthorised access will be assessed.The exchange itself deserves particular attention. Email attachments and unrestricted public links can make it harder to control recipients, availability and evidence. A controlled B2B file-exchange process helps define the handoff when personal information moves between organisations.
Platform roleSupport privacy through controlled exchangeHow My MX Data contributes to stronger information handling
My MX Data is a secure B2B file-exchange platform. MX helps organisations direct files to approved or named recipients, apply multi-factor authentication and define how long access remains available.
AES-256 encryption forms part of the wider security model. Detailed transaction records can show uploads, access, downloads, comments and recipient activity, helping administrators review what happened during an exchange. Relevant configurations may also support data-location requirements, secure upload portals and enterprise identity controls.
These features can support privacy and compliance objectives by reducing uncertainty around external transfers. They do not establish the legal basis for processing, decide retention policy or replace staff training, contracts and legal assessment.
Privacy law depends on context.Jurisdiction, sector, business size, data type, processing purpose and contractual relationships can all affect the legal position. Organisations should verify current regulator guidance and obtain specialist advice where the risk or complexity justifies it.
Data privacy becomes more manageable when the organisation can trace the information from collection to deletion. The law may differ by country, but disciplined handling, restrained access and clear evidence remain useful wherever the file travels.