User Research Privacy Laws Beyond GDPR and CCPA: Brazil, Canada, India, Japan, China and More
Most research compliance guidance stops at the EU and California. Here is what actually applies when you interview customers in Brazil, Canada, India, Japan, China, South Korea, Australia and South Africa — which law reaches you, what legal basis works, and the one design that satisfies all of them.
Answer first: if you interview customers outside the EU and the United States, at least six other national privacy regimes can reach you — and the differences that matter for research are not about data transfers, they are about which legal basis you are allowed to rely on and whether the law reaches a foreign company at all. Brazil, Canada, India, Japan, China, South Korea, Australia and South Africa each answer those two questions differently. This guide maps them for customer research specifically, and ends with the single study design that satisfies the strictest of them, so you do not have to run eight variants of the same interview.
This is the which law applies question. If your question is where the recordings physically sit and how they legally cross a border, read research data residency and international transfers instead — that is the transfer mechanism, and it is a separate problem from the one below.
The two questions that decide everything
1. Does the law reach you? Almost all of these regimes have some form of extraterritorial reach, but the trigger differs. Brazil's LGPD applies if the processing takes place in Brazil, the data was collected in Brazil, or the purpose is offering goods or services in Brazil. China's PIPL reaches foreign entities processing the personal information of people in China for the purpose of providing products or services to them. Others, notably Canada's PIPEDA, hinge more on a real and substantial connection to the country. The practical test for a research team is: are you recruiting people located in that country to talk about a product you offer there? If yes, assume the law reaches you.
2. What can you rely on to process the data? This is where the regimes genuinely diverge, and where copy-pasting a GDPR consent form goes wrong in both directions — sometimes it collects consent you did not need, and sometimes it fails to collect consent you did.
| Jurisdiction | Law | Consent-first or basis-flexible? | What this means for interviews |
|---|---|---|---|
| Brazil | LGPD | Ten legal bases, including legitimate interests | Consent is not your only option, but legitimate interests is unavailable for sensitive data |
| Canada (federal) | PIPEDA | Consent-centric, with meaningful-consent expectations | Purposes must be explained in plain language a person would actually understand |
| Quebec | Law 25 | Opt-in consent, notably strict | Separate express consent expectations and automated-decision transparency |
| India | DPDP Act 2023 + Rules 2025 | Consent-first, with narrow "legitimate uses" | Notice must be clear, standalone, and available in scheduled Indian languages |
| Japan | APPI | Purpose-specification model rather than a consent-for-everything model | Specify the purpose of use and stay inside it; consent is required for third-party provision and most transfers abroad |
| China | PIPL | Consent-first, with separate consent for sensitive data and for transfers abroad | Separate, specific consent — not a bundled checkbox |
| South Korea | PIPA | Consent-first and highly granular | Consent items must be itemised and separately agreed |
| Australia | Privacy Act / APPs | Notice-and-purpose model | Collection notice under APP 5; sensitive information generally needs consent |
| South Africa | POPIA | Six lawful justifications including legitimate interest | Close in structure to GDPR; an Information Officer must be registered |
Brazil: LGPD
The LGPD's structure will feel familiar to anyone who has worked with the GDPR: ten legal bases, data subject rights, and a regulator, the ANPD, that has become considerably more active. For research, two points matter most.
First, legitimate interests is a genuine option, and the ANPD published guidance in February 2024 setting out a three-stage balancing test — purpose, necessity, then balancing and safeguards. If your interviews are with existing customers about a product they already use, that is close to the paradigm case of a reasonable expectation.
Second, and decisively: the ANPD has reaffirmed that legitimate interests cannot be used for sensitive personal data. Interviews are leaky. A conversation about a banking app produces financial hardship disclosures; one about a fitness product produces health data. If your study is likely to surface sensitive categories, you need consent for that portion, and data subjects retain the right to object to legitimate-interest processing. Plan for the leak rather than being surprised by it.
Canada: PIPEDA, and the reform that did not happen
PIPEDA remains the federal private-sector law. Bill C-27, which would have replaced it with the Consumer Privacy Protection Act and added an AI statute, died when Parliament was prorogued in January 2025 and has not been re-enacted. Plan against PIPEDA as it stands, not against the bill.
PIPEDA is consent-centric, and its distinguishing feature is the meaningful consent standard: the regulator expects that people actually understand what they are agreeing to, with emphasis on what is collected, who it is shared with, the purposes, and the residual risk of harm. A dense scroll box does not clear that bar.
Quebec is the separate problem. Law 25 imposes opt-in consent, requires an assessment of whether collection is necessary, legitimate and proportionate to the purpose, requires parental consent for under-14s, and requires that people be informed when personal information is used to make an automated decision. If your research uses AI-moderated interviews with Quebec residents, treat that automated-decision transparency requirement as live and describe the AI's role explicitly.
India: the DPDP Act and the 2025 Rules
India's Digital Personal Data Protection Act 2023 finally became operational when the DPDP Rules were notified on 14 November 2025, opening a phased implementation window with substantive obligations on data fiduciaries landing through to 13 May 2027. Treat 2026 as a build-and-test year, not a grace period you can ignore.
Three features matter for research:
- Consent is the primary route. The Act's alternative, "certain legitimate uses," is a narrow enumerated list, not a flexible balancing test. For customer interviews, get consent.
- The notice standard is unusually prescriptive. Notice must be clear, standalone, understandable independently of any other document, and available in English or any language in the Eighth Schedule to the Constitution. A privacy notice in English only, buried inside terms of service, does not comply.
- Withdrawal must be as easy as giving consent, and a Consent Manager framework is being operationalised through 2026 to let people manage consent across services.
Japan: purpose specification, not consent theatre
Japan's APPI is often misdescribed as a consent regime. It is closer to a purpose-specification regime: you must specify the purpose of use, notify or publicly announce it, and not exceed it without fresh consent. Where consent is genuinely required is for providing data to third parties and, generally, for transfers to other countries.
Japan is also mid-reform. A Cabinet-approved amendment bill passed the Diet on 10 July 2026 and was promulgated on 17 July 2026, extending protection to "contactable" identifiers such as email addresses, phone numbers and device or cookie IDs, adding a specific category for biometric information, and strengthening protection for under-16s. The new regime is enacted but not yet in force — a cabinet order will set the effective date, no later than July 2028. Nothing changes today; everything changes before your current consent language is retired.
China: separate consent, every time
PIPL is the strictest of the group for research, and the reason is a single word: separate. Bundled consent that covers everything in one checkbox is precisely what PIPL is designed to prohibit. You need separate consent for processing sensitive personal information, and separate consent for providing personal information to recipients outside China — which is what happens the instant an interview recording lands on a server elsewhere.
Also note that sensitive personal information under PIPL requires that you inform people of the necessity of the processing and the impact on their rights. If you are running research in mainland China at any scale, the transfer mechanism and the consent architecture need local advice; this is not a jurisdiction to improvise in.
Australia, South Korea and South Africa in brief
Australia works on a notice-and-purpose model. APP 5 requires a collection notice at or before the time of collection, and sensitive information generally requires consent plus a direct relationship to your functions. The Privacy Act has been under a multi-tranche reform programme since 2024; watch it, but the APPs remain the operative rules.
South Korea's PIPA is consent-first and granular in a way that surprises teams used to a single checkbox: consent items are expected to be itemised and separately agreed, so that a person can agree to the interview and decline the optional marketing follow-up. The PIPC has continued tightening guidance on how choices must be presented.
South Africa's POPIA is structurally close to GDPR — six lawful justifications including legitimate interest, plus a registered Information Officer and a set of conditions for lawful processing. If your GDPR programme is real, POPIA is mostly a mapping exercise.
The one design that satisfies all of them
You do not need eight study variants. Build to the strictest common denominator and the rest follow:
- Separate, specific, opt-in consent captured at the start of the interview, not buried in a recruitment email. This satisfies PIPL, PIPA, DPDP and Law 25, and over-satisfies LGPD and APPI without breaking them.
- Itemise the consents. Recording, transcription, AI processing, quoting, retention period and any third-party sharing should each be separately agreeable. Bundling is the single most common failure across these regimes.
- Name the AI explicitly. Say that an AI conducts the interview, what it does with the responses, and that a human reviews outputs. This covers Quebec's automated-decision notice, the DPDP notice standard, and the transparency expectations of every regime here.
- Localise the notice, not just the questions. India effectively requires it; Japan, Korea and Brazil expect comprehension in practice. Koji runs interviews in the participant's language — see multi-language user research — and the consent text must be localised with them, not left in English.
- Design for the sensitive-data leak. Interviews wander into health, finances and family. Either take explicit consent for sensitive categories up front, or instruct the interviewer not to probe them and redact what arrives anyway.
- Make withdrawal real and easy, with a stated retention period and a deletion path that reaches exports too.
- Minimise at the source. The less identifiable data you collect, the less of this applies.
That last point is where study design does real compliance work. Koji's six structured question types — open_ended, scale, single_choice, multiple_choice, ranking and yes_no — let you capture most of what a study needs as structured, aggregate-safe values rather than as free text that inevitably contains names, employers and disclosures. A study whose quantitative backbone is scales, choices and rankings, with open-ended probing reserved for the questions that genuinely need reasoning, carries dramatically less personal data across every border in this article. Koji's AI interviewer still probes the open questions properly, so you lose no depth — you just stop collecting identifiable text you were never going to use.
A working checklist
| Step | Action |
|---|---|
| 1 | List every country your participants are physically located in — not where your company is |
| 2 | For each, decide whether the law reaches you (offering services there is usually enough) |
| 3 | Pick a legal basis per country; default to explicit, itemised consent |
| 4 | Localise notice and consent into the participant's language |
| 5 | Decide in advance how sensitive disclosures are handled and redacted |
| 6 | Confirm the transfer mechanism separately — that is a different analysis |
| 7 | Record the assessment; accountability means being able to show your reasoning |
Frequently asked questions
Does my company need to comply with these laws if we have no office in that country? Usually yes, at least for the ones with extraterritorial reach. Brazil's LGPD, China's PIPL and India's DPDP Act all contemplate foreign companies that offer goods or services to people in those countries. Physical presence is not the test; the location of the person you are interviewing and the market you are selling into usually are.
Can I reuse my GDPR consent form for research in Brazil, India and Japan? Not without modification, in both directions. A GDPR form may collect consent where Brazil would let you rely on legitimate interests, and it may be too bundled for China and South Korea, which expect separate consent per purpose. It will also miss India's requirement for a standalone notice available in scheduled Indian languages. Start from the GDPR form, then itemise and localise.
Which of these laws is strictest for customer interviews? China's PIPL, because of the separate-consent requirements for sensitive information and for sending data outside China, followed by South Korea's PIPA for consent granularity and Quebec's Law 25 for opt-in strictness. If you design to satisfy those three, the rest are comfortably covered.
Did Canada's privacy law change with Bill C-27? No. Bill C-27 died when Parliament was prorogued in January 2025, so the Consumer Privacy Protection Act and the proposed AI statute never became law. PIPEDA remains in force federally, alongside Quebec's Law 25 and the other substantially-similar provincial regimes.
Do these laws treat B2B research participants differently? Less often than US state laws do. The US state model of excluding people acting in a commercial or employment context is unusual; most of the regimes here protect individuals regardless of whether they are speaking as a professional. Assume your B2B participants are covered.
What about the transfer of recordings out of the country? That is a separate legal question from which law applies, and it has its own mechanisms — adequacy findings, standard contractual clauses, security assessments and, in China's case, separate consent. Do the applicability analysis first, then the transfer analysis.
Related Resources
- Structured Questions Guide — the six question types that minimise the personal data a study collects
- Research Data Residency and International Transfers — the transfer-mechanism half of the problem
- GDPR-Compliant AI User Research — the EU baseline these regimes are usually compared against
- US State Privacy Laws for Customer Research — the twenty-state American patchwork
- Multi-Language User Research — running and localising interviews in the participant's language
- Interview Recording Consent Laws — the recording-specific consent rules
- Research Data Access Controls and Audit Trails — proving who could see the data afterwards
Related Articles
GDPR-Compliant AI User Research: A Practical Guide
How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.
Interview Recording Consent Laws: One-Party, All-Party, and Biometric Rules (2026)
Federal law allows one-party consent recording, but roughly a dozen US states require all-party consent - and biometric laws like Illinois BIPA add a separate written-consent duty for voiceprints. Here is how research teams stay on the safe side of both.
Multi-Language User Research: How to Interview Participants in Any Language
How to configure Koji to run voice and text interviews in 15+ languages — including brief localization, cross-market analysis, and synthesis best practices.
Research Consent Form Templates: GDPR-Compliant Forms for Every Study
Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.
Research Data Access Controls and Audit Trails: Who Can See Your Interview Data
Your vendor's SOC 2 report proves the vendor is secure. It says nothing about which colleague opened a raw transcript last Tuesday. Here is how to build access tiers, audit trails and access reviews for research data — and what an auditor will actually ask you for.
Research Data Residency and International Transfers: Where Your Interview Data Actually Lives
Data residency, sovereignty, and localisation explained for research teams — GDPR Chapter V transfer mechanisms, transfer impact assessments, the DPF's current status, and the questions to ask any research vendor.
Structured Questions in AI Interviews
Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.
US State Privacy Laws for Customer Research: The Multi-State Compliance Guide (2026)
Twenty states now have comprehensive privacy laws and they do not agree with each other. Here is what actually applies to research interviews, why most B2B participants fall outside every law except California, and how to build one compliant process instead of twenty.