Which of the following adopted a law on data protection and privacy for its citizens known as ‘General Data Protection Regulation’ in April 2016 and started implementation of its from 25th May, 2018?

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2019, Q104

Contents8
UPSC Prelims GS2019World Affairs (International Relations)
  1. AAustralia
  2. BCanada
  3. CThe European Union
  4. DThe United States of America
Show answer

Answer: (C) The European Union

The correct answer is (C) — The European Union.

The General Data Protection Regulation (GDPR) is one of the world's strongest data privacy laws.

It was adopted by the EU Parliament in April 2016 and came into effect on May 25, 2018.

It protects the personal data and privacy of all EU citizens.

Tip: GDPR = EU's landmark privacy law.

It has become a global benchmark for data protection.

Why this was asked

GDPR became the world's strictest data privacy law, affecting any company that handles EU citizen data regardless of where the company is located.

The 2016-2018 period saw major data breaches like Cambridge Analytica, making data protection a critical global policy issue that UPSC needed to test.

The question tests whether students can distinguish EU regulatory leadership from other major economies in the emerging field of digital governance.

General Data Protection Regulation (GDPR)

World Affairs (International Relations) General Data Protection Regulation GDPR April 2016 25th May 2018

GDPR: EU's Landmark Data Privacy Law & Global Impact

Must know

GDPR adopted by EU Parliament in April 2016, implemented from 25 May 2018

World's strongest data privacy law protecting all EU citizens' personal data

Good to know

Creates extraterritorial jurisdiction - applies to non-EU companies processing EU data

Fines up to 4% of global turnover or €20 million, whichever is higher

The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy framework that revolutionized global data protection standards. It grants EU citizens unprecedented control over their personal data and has become the international benchmark for privacy legislation.

GDPR Key Provisions

Aspect

Key Feature

Impact

Territorial Scope

Applies to all EU data processing + non-EU companies serving EU citizens

Global compliance requirement

Individual Rights

Right to access, rectify, erase ('right to be forgotten'), data portability

Enhanced citizen control

Consent

Explicit, informed, freely given consent required

Stricter opt-in requirements

Data Breach

Must notify authorities within 72 hours

Faster incident response

Penalties

Up to 4% global turnover or €20 million

Severe financial deterrent

This question tests knowledge of timeline and jurisdiction - GDPR was adopted in April 2016 but implementation began on 25 May 2018. The EU's regulatory leadership in digital governance has influenced similar laws worldwide, including India's Personal Data Protection Bill.

Exam traps

Date confusion: GDPR was adopted in April 2016 but implemented from May 2018 - don't mix the dates

Jurisdiction trap: While US states like California have data laws, GDPR is specifically EU legislation

Australia confusion: Australia has Privacy Act but not GDPR - don't confuse similar-sounding data protection laws

Global Data Protection Laws Comparison

World Affairs (International Relations)

Major Data Protection Laws Worldwide: Comparative Analysis

Must know

EU GDPR (2018) sets global gold standard for comprehensive data protection

Good to know

California CCPA (2020) is strongest US state-level privacy law

India's PDP Bill draws heavily from GDPR framework

Major Data Protection Laws

Country/Region

Law

Year Effective

Key Features

European Union

GDPR

2018

Comprehensive rights, extraterritorial scope, heavy fines

United States

CCPA (California)

2020

State-level, right to know/delete, opt-out of sale

Canada

PIPEDA

2001

Private sector focus, reasonableness standard

Australia

Privacy Act

1988 (amended)

Notifiable data breach scheme since 2022

India

PDP Bill (proposed)

Pending

GDPR-inspired, data localization requirements

Regulatory fragmentation: Different countries developing incompatible privacy frameworks

GDPR influence: Many jurisdictions adopting GDPR-like provisions as global standard

Cross-border compliance: Companies face complex multi-jurisdictional requirements

Enforcement variation: EU leads in active enforcement, others still building capacity

Exam traps

US federal confusion: No comprehensive federal data law in US - only state-level laws like CCPA

Canada timing: PIPEDA predates GDPR by decades but is less comprehensive

Australia scope: Privacy Act covers both public and private sectors, unlike some other laws

India's Data Protection Framework

World Affairs (International Relations)

India's Evolving Data Protection Landscape

Must know

Personal Data Protection Bill modeled on GDPR but with data localization requirements

Good to know

Justice Srikrishna Committee (2018) provided foundational recommendations

IT Rules 2021 provide interim data protection for social media platforms

India is developing comprehensive data protection legislation influenced by GDPR but tailored to national priorities. The framework emphasizes data localization and digital sovereignty alongside individual privacy rights.

India's Data Protection Evolution

Development

Year

Key Provisions

Puttaswamy Judgment

2017

Privacy as fundamental right under Article 21

Srikrishna Committee Report

2018

GDPR-based framework with data localization

PDP Bill 2019

2019

Comprehensive data protection, Data Protection Authority

IT Rules 2021

2021

Social media compliance, grievance redressal mechanisms

Digital Personal Data Protection Act

2023

Simplified framework replacing earlier bills

Unique Indian Features

Data localization: Critical personal data must be stored within India

Government exemptions: National security and law enforcement carve-outs

Cross-border transfers: Restricted to approved countries with adequate protection

Consent managers: Technical infrastructure for managing user consent

Exam traps

Multiple bills: India has had several versions of data protection bills - don't confuse timelines

Constitutional basis: Privacy right comes from Puttaswamy judgment (2017), not original Constitution

Implementation gap: Laws passed but enforcement mechanisms still being developed