Field Reference · Edition 2 All resources →

AI & DATA REGULATION · EIGHT JURISDICTIONS

Navigating the Legal Landscape.

If your organization touches data or AI across borders, you're living inside four questions: What protects the data? What governs the AI? What controls the transfer? And where must the data physically stay? This brief answers all four across the EU, UK, US, China, Canada, Brazil, India, and South Korea — every answer sourced, tiered, and dated.

Edition 2 · verified through 28 Aug 2026 · 23 pages
Cover of Navigating the Legal Landscape: AI & Data Regulation, Edition 2

A report about data should be data. Download the full PDF — and the complete verified dataset behind it, machine-readable for your compliance team, your spreadsheet, or your AI agents.

Four dimensions. Eight anchors. Dated answers.

Every jurisdiction is read through the same four questions, and every answer carries its governing instrument, its status, four separate dates, and a source tier — because blending "enacted," "in force," "rules effective," and "when we looked" is the most common way a regulatory claim goes quietly wrong.

01

Data protection

The settled layer — but "settled" doesn't mean still. Korea's new 10%-of-turnover penalty tier, the UK's DUAA amendments, and India's phased DPDP runway all land inside this edition.

02

AI regulation

The in-force comprehensive-statute cohort is smaller than the headlines suggest — the EU's phased AI Act and Korea's Framework Act lead it, while China binds hardest without an omnibus law at all.

03

Cross-border transfer

Where regimes diverge hardest: the EU's adequacy web, China's authorization-and-threshold model, the US DOJ Data Security Program, and India's enacted-but-not-yet-operative blacklist.

04

Data localization

Narrower than feared — mostly sectoral. And where we couldn't support a clean answer, the dataset says so explicitly: two cells ship as honest published gaps, not confident-sounding guesses.

The calendar is the compliance document.

Already-fixed dates between now and 2028 — none of them predictions; each read from the governing instrument, dated, and sourced in the dataset:

  • 11 SEP 2026South Korea's aggravated penalty tier (up to 10% of total turnover) applies.
  • ≈13–14 NOV 2026India's Consent Manager tranche commences.
  • 1 JAN 2027Colorado's AI Act developer and deployer duties take effect.
  • ≈13 MAY 2027India's DPDP substantive core lands.
  • 2 DEC 2027 / 2 AUG 2028The EU AI Act's deferred high-risk obligations arrive.

The dataset is the product, too.

Every jurisdiction-dimension record ships with its status, governing instrument, four separate dates, source tier, confidence rating, and verification date — as JSON and CSV. The files carry their own machine-readable notice, so an AI agent that finds them learns the same thing a human reader does: this is general information, dated, and no substitute for counsel.

30 records4 dates per recordsource-tieredJSON + CSVEdition 2

Why you can lean on it

The least-certain readings are flagged on a public watchlist. Edition 2 publishes its own revision record rather than silently overwriting Edition 1. Primary instruments were read where it counts — official gazettes, EUR-Lex, and government legal portals. You don't have to take our word for any claim — the dataset tells you exactly where each one came from.

© 2026 DataExos, LLC. General information, not legal advice — see the Legal, Reliance, and Liability Notice on p. 21 of the report. Written with AI assistance — How We Write Here