birthday.gold
← Legal hub

Your data rights

You can request a copy of your data or delete your account anytime from your account settings. We honor the major data-protection regulations below.

Brasil’s Lei Geral de Proteção de Dados (LGPD)
Region: LATAM (Latin America) Lei Geral de Proteção de Dados (LGPD) is a comprehensive data protection law in Brazil that takes its inspiration from the EU’s GDPR. The data protection law applies to all data subjects located in Brazil and who are served different products or services from companies operating inside or outside Brazil and to public authorities in Brazil. The law establishes ten legal bases for the lawful processing and handling of data, as well as accountability requirements, mandatory breach notifications and DSRs - imposing heavy penalties upon violation.
California Consumer Privacy Act
California Privacy Rights Act
Colorado Privacy Act
Connecticut Personal Data Privacy and Online Monitoring Act
EU’s General Data Protection Regulation (GDPR)
Region: EMEA (Europe, the Middle East and Africa) The European Union’s General Data Protection Regulation (GDPR) is considered to be the most comprehensive data protection legal framework that aims to protect personal data of natural persons and grants several rights to them. The regulation applies to companies established in the EU. It also applies to organizations not established in the EU that monitor individuals’ behavior in the EU or offer goods or services to data subjects in the EU. Inspired by the GDPR, countries all around the world have formulated their data protection laws based on the similar framework.
Personal Data Protection Regulations in Force in Costa Rica
Law No. 8968, on the Protection of the Individual against the Processing of Personal Data. The bill was processed under file No. 16,679 and is an initiative of deputies from various political factions. It was approved on June 27, 2011 and published in La Gaceta No. 170 of September 05, 2011. In 2012, through Executive Decree No. 37554-JP, the Regulations to Law No. 8968 were issued. To date, the Law has not been reformed, while Executive Decrees No. 40008-JP in 2016 and No. 41582 in 2019 amended some articles of the Regulations.
Personal Information Protection and Electronic Documents Act (PIPEDA)
Region: NA (North America) PIPEDA is a federal law that governs the data collection, processing, and protection by federal works, undertakings or businesses operating within Canada. The data privacy and protection regulations were enacted to assure the global community of the data protection practices and compliance of the Canadian private sector. The regulations apply to for-profit federally regulated organizations offering commercial services in Canada such as banks, radio and television studios, airports and airlines, inter-provincial trucking, telecommunication companies, railways etc.
Privacy Act
UK Data Protection Act (DPA)
Region: EMEA (Europe, the Middle East and Africa) The UK Data Protection Act (DPA) 2018 is the amended version of the Data Protection Act that was passed in 1998. The DPA 2018 implements the GDPR with several additions and restrictions. The DPA 2018 is divided into three kinds of processing including general data processing, processing by law-enforcement agencies, and processing by intelligence services. The DPA 2018 must be read together with the UK GDPR, which is the GDPR as it was on 31st December 2020 and any applicable case law at that point.
Utah Consumer Privacy Act
Virginia Consumer Data Protection Act