Skip to content
Scheidegger Webpublishing Webpublishing, Bern

Web regulation / Rest of the world

The rest of the world, and the principle behind all of it

Around a hundred states now have personal data legislation. Listing them would serve no purpose. Understanding what they share does, because it lets you decide without seeking advice every time.

File verified on 27 July 2026.

The law follows the visitor, not the server

Since the GDPR, almost every law adopted around the world uses the same connecting factor: what governs is where the person whose data is processed is located, not where the machine runs. The era of choosing your law by choosing your host is over.

That observation has a pleasant practical consequence. A site that collects only what it needs, hands nothing to third parties and follows nobody satisfies almost all of these regimes by construction, without having to read them. Compliance is expensive when bolted on afterwards; it is nearly free when it is the starting point.

United Kingdom

Leaving the Union did not carry the regime away with it. The UK GDPR and the Data Protection Act 2018 keep the same architecture, and cookie storage falls under a separate text, the Privacy and Electronic Communications Regulations, which requires prior consent as on the continent.

The framework was amended in 2025 and the supervisory authority publishes up-to-date guidance. For a Swiss site the practical conclusion is unchanged: whatever satisfies the European regime satisfies the British one.

California

The Californian regime does not resemble the European one. It rests not on prior consent but on a right to opt out, and it applies only above thresholds: doing business in California and, at your choice, exceeding twenty-five million dollars of annual gross revenue, processing the data of a hundred thousand consumers or households, or deriving half your revenue from selling or sharing personal information.

In other words a small Swiss business is almost never caught by it. The point is worth knowing because people are regularly sold the opposite.

Brazil, Canada, and the others

Brazil’s LGPD is the closest relative of the GDPR outside Europe, down to its extraterritorial reach. Canada combines a federal private-sector privacy act with an anti-spam law of some severity, which targets the sending of commercial messages rather than websites themselves.

For everything else, the cautious rule fits in one sentence: if you actively solicit a country, look into that country. If you merely happen to be readable there, the baseline described above suffices in the vast majority of cases.

Continue

The three parts

What Swiss law asks of a website

Switzerland is more permissive than the European Union on cookies, and stricter than people assume on personal liability. The four points below cover almost every case of a presentation site or an editorial site.

Read this part

When European law reaches a Swiss website

Many Swiss businesses believe European law has no bearing on them because their server sits in Switzerland. The test has never been the server. It is the audience addressed.

Read this part