Start for free
Pivlu AI Assistant

Privacy Laws We Cover

Pivlu Consent automatically adapts to the visitor's location and applies the correct consent mode — opt-in for GDPR-style laws, opt-out for US state privacy laws.

Coverage at a glance

30+
Countries covered
14
US states covered
2
Consent modes (opt-in & opt-out)
🇪🇺

European Union & EEA

The EU has the strictest data protection framework in the world. Pivlu Consent applies full opt-in consent for all EU/EEA visitors — no cookies or tracking scripts run until the user explicitly accepts.

GDPR — General Data Protection Regulation

Opt-in consent

The EU's comprehensive data protection law, effective since May 2018. Applies to all 27 EU member states plus the EEA (Norway, Iceland, Liechtenstein). Requires explicit, informed consent before any non-essential data processing.

Countries: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Norway, Iceland, Liechtenstein.
Key requirements: Prior consent for cookies, right to withdraw, data access/deletion rights, DPO appointment, data breach notification within 72 hours.
How Pivlu handles it: Full opt-in banner with category toggles. All non-essential scripts are blocked until the visitor actively consents. Consent is logged with timestamp and categories for audit compliance.

ePrivacy Directive — Cookie Law

Opt-in consent

The EU's directive specifically targeting electronic communications and cookies. Works alongside GDPR — while GDPR covers data protection broadly, ePrivacy specifically requires consent for storing cookies or accessing device information.

Countries: All 27 EU member states + EEA.
Key requirements: Consent before placing cookies, clear information about cookie purposes, ability to refuse without service degradation.
How Pivlu handles it: Same opt-in mechanism as GDPR. Cookie categories (analytics, marketing, preferences, social) give visitors granular control.
🇬🇧

United Kingdom

After Brexit, the UK adopted its own version of GDPR with nearly identical requirements.

UK GDPR — United Kingdom General Data Protection Regulation

Opt-in consent

The UK's post-Brexit data protection framework, maintained under the Data Protection Act 2018. Mirrors the EU GDPR in substance — explicit consent is required before placing non-essential cookies.

Key requirements: Same as EU GDPR — prior consent, data subject rights, breach notification, DPO where required.
How Pivlu handles it: UK visitors see the full opt-in consent banner, identical to EU GDPR mode.
🇺🇸

United States

The US has no federal privacy law, but 14 states have enacted their own data privacy laws. All follow an opt-out model — scripts run by default, but visitors must be able to opt out of the sale or sharing of their personal information.

CCPA/CPRA — California Consumer Privacy Act / California Privacy Rights Act

Opt-out model

The most well-known US state privacy law. Gives California residents the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale or sharing. CPRA (effective 2023) strengthened CCPA with additional rights.

Key requirements: "Do Not Sell or Share My Personal Information" opt-out, privacy policy disclosures, data access and deletion rights, no discrimination for exercising rights.
How Pivlu handles it: California visitors see a CCPA opt-out notice with "Do Not Sell" option. Scripts run by default. Meta Limited Data Use (LDU) is automatically applied when opted out.

CalOPPA — California Online Privacy Protection Act

Opt-out model

One of the first US online privacy laws (2004). Requires websites that collect personal information from California residents to conspicuously post a privacy policy. Works alongside CCPA/CPRA.

Key requirements: Conspicuous privacy policy, disclosure of data collected and third parties, honor "Do Not Track" signals, notify users of policy changes.
How Pivlu handles it: CCPA opt-out mode covers CalOPPA requirements. Pivlu's AI Privacy Policy generator creates CalOPPA-compliant disclosures.

VCDPA — Virginia Consumer Data Protection Act

Opt-out model

Virginia's privacy law, effective January 2023. Gives consumers the right to access, correct, delete, and port their data, and to opt out of targeted advertising, sale of personal data, and profiling.

Key requirements: Opt-out rights for targeted ads and data sales, data protection assessments, privacy notice requirements.
How Pivlu handles it: Virginia visitors see the opt-out consent notice. Denied categories trigger cookie cleanup and script blocking.

CPA — Colorado Privacy Act

Opt-out model

Colorado's privacy law, effective July 2023. Similar to VCDPA with opt-out rights for targeted advertising and sale of personal data. Requires universal opt-out mechanism recognition.

Key requirements: Universal opt-out mechanism support, opt-out of targeted advertising and data sales, data protection assessments.
How Pivlu handles it: Colorado visitors see the opt-out consent notice with "Do Not Sell" option.

CTDPA — Connecticut Data Privacy Act

Opt-out model

Connecticut's privacy law, effective July 2023. Provides consumers with rights to access, correct, delete, and port their data, and to opt out of targeted advertising and data sales.

Key requirements: Opt-out rights, universal opt-out mechanism support, data protection assessments, privacy notices.
How Pivlu handles it: Connecticut visitors see the opt-out consent notice.

TDPSA — Texas Data Privacy and Security Act

Opt-out model

Texas's privacy law, effective July 2024. Applies to businesses operating in Texas that process personal data. Provides standard consumer privacy rights and opt-out mechanisms.

Key requirements: Opt-out of data sales, targeted advertising, and profiling; privacy notice requirements; data protection assessments.
How Pivlu handles it: Texas visitors see the opt-out consent notice.

FDBR — Florida Digital Bill of Rights

Opt-out model

Florida's privacy law, effective July 2024. Applies to businesses with over $1 billion in revenue or that operate certain types of platforms. Provides consumer rights similar to other US state laws.

Key requirements: Opt-out of targeted advertising and data sales, data access and deletion rights, children's data protections.
How Pivlu handles it: Florida visitors see the opt-out consent notice.

UCPA — Utah Consumer Privacy Act

Opt-out model

Utah's privacy law, effective December 2023. The most business-friendly of the US state privacy laws, with narrower consumer rights but still requiring opt-out mechanisms for data sales and targeted advertising.

Key requirements: Opt-out of data sales and targeted advertising, privacy notice, data access and deletion rights.
How Pivlu handles it: Utah visitors see the opt-out consent notice.

MCDPA, OCPA, TIPA, ICDPA, DPDPA, NJDPA, NHDPA

Opt-out model

Additional US state privacy laws enacted in Montana, Oregon, Tennessee, Iowa, Delaware, New Jersey, and New Hampshire. All follow the same opt-out model with consumer rights to access, delete, and opt out of data sales and targeted advertising.

States: Montana (MCDPA), Oregon (OCPA), Tennessee (TIPA), Iowa (ICDPA), Delaware (DPDPA), New Jersey (NJDPA), New Hampshire (NHDPA).
How Pivlu handles it: Visitors from these states see the opt-out consent notice. Pivlu auto-detects the visitor's state via GeoIP and applies the correct mode.
🌍

Worldwide

Privacy regulations are expanding globally. Pivlu Consent covers major international privacy laws with the appropriate consent mode.

FADP — Swiss Federal Act on Data Protection

Opt-in consent

Switzerland's data protection law, revised in September 2023 to align closely with the EU GDPR. Requires consent for non-essential data processing and provides individuals with rights to access, correct, and delete their data.

Country: Switzerland.
Key requirements: Consent before data processing, privacy by design, data breach notification, data protection impact assessments.
How Pivlu handles it: Swiss visitors see the full opt-in consent banner, same as GDPR mode.

PIPEDA — Personal Information Protection and Electronic Documents Act

Opt-in consent

Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information. Requires meaningful consent and gives individuals the right to access and challenge the accuracy of their information.

Country: Canada (all provinces, with provincial equivalents in Quebec, Alberta, and British Columbia).
Key requirements: Meaningful consent, purpose limitation, data minimization, individual access rights, accountability.
How Pivlu handles it: Canadian visitors see the opt-in consent banner. Scripts are blocked until consent is given.

Quebec's Law 25 — Act Respecting the Protection of Personal Information in the Private Sector

Opt-in consent

Quebec's modernized privacy law, fully effective September 2024. The strongest provincial privacy law in Canada — closely mirrors GDPR with explicit consent requirements, privacy impact assessments, and significant penalties.

Region: Quebec, Canada.
Key requirements: Express consent for sensitive data, privacy impact assessments, data breach notification, privacy officer appointment, right to data portability.
How Pivlu handles it: Quebec visitors (detected as Canadian) see the opt-in consent banner.

POPIA — Protection of Personal Information Act

Opt-in consent

South Africa's data protection law, fully enforceable since July 2021. Modeled after the EU GDPR, it requires consent for processing personal information and provides individuals with rights to access, correct, and delete their data.

Country: South Africa.
Key requirements: Consent before processing, purpose limitation, data minimization, information officer appointment, data breach notification.
How Pivlu handles it: South African visitors see the opt-in consent banner, same as GDPR mode.

LGPD — Lei Geral de Proteção de Dados

Opt-in consent

Brazil's comprehensive data protection law, effective since September 2020. Closely modeled after the EU GDPR, it applies to any organization that processes personal data of individuals in Brazil, regardless of where the organization is based.

Country: Brazil.
Key requirements: Legal basis for processing (consent is primary), data subject rights (access, correction, deletion, portability), DPO appointment, data breach notification.
How Pivlu handles it: Brazilian visitors see the opt-in consent banner, same as GDPR mode.

How Pivlu detects and applies the right law

Automatic compliance based on visitor location — no manual configuration needed.

GeoIP Detection

When a visitor loads your page, Pivlu detects their country and US state via GeoIP database. No third-party API calls — detection happens on your server instantly.

Regulation Routing

Based on location, Pivlu automatically selects the correct consent mode: opt-in (GDPR-style) for EU, UK, Canada, South Africa, Brazil, Switzerland — opt-out for US states with privacy laws.

Automatic Compliance

The consent banner adapts its behavior — blocking scripts until consent in opt-in mode, or showing a "Do Not Sell" notice in opt-out mode. Visitors from non-regulated regions see no banner.