Compliance
Every regime the consent engine detects, and what it does about it.
StrongPrivacy resolves a visitor’s country (and, for California and Quebec, their region) onto one of ten legal regimes, then applies a consent model. These pages describe each regime and the exact behaviour that follows.
GDPR (European Economic Area)
In the European Economic Area, consent has to be given before non-exempt storage or access occurs, not recorded after the fact. StrongPrivacy detects all 30 EEA countries and resolves them to an opt-in model under all four current region profiles.
Law: Regulation (EU) 2016/679, with Directive 2002/58/EC
UK GDPR and PECR
The United Kingdom kept the substance of the EU regime and changed the machinery around it. A visitor from GB is detected as UK GDPR rather than GDPR, which matters less for the banner than for who enforces it and what exceptions are opening up.
Law: UK GDPR, Data Protection Act 2018, PECR 2003
CCPA / CPRA (California)
California is the one regime in the built-in set that resolves to an opt-out model rather than opt-in, and the one where a browser signal, not a click, can be the decision.
Law: CCPA (2018) as amended by the CPRA (2020)
LGPD (Brazil)
The LGPD is structurally close to the GDPR (ten legal bases, a national authority, real fines), but it has no ePrivacy counterpart. The consent question therefore turns on which basis you are relying on for the processing itself.
Law: Lei nº 13.709/2018 (LGPD)
Law 25 (Quebec)
Quebec is detected separately from the rest of Canada, because Law 25 asks for something the federal statute does not: technology that identifies, locates or profiles must be off until the person turns it on.
Law: Law 25 (formerly Bill 64), amending Quebec’s Private Sector Act
PIPEDA (Canada)
Canada’s federal statute allows implied consent for non-sensitive purposes, which makes it more permissive than the EEA on paper. StrongPrivacy still treats a Canadian visitor as opt-in, and this page explains that choice rather than hiding it.
Law: Personal Information Protection and Electronic Documents Act
FADP (Switzerland)
Switzerland is not in the EEA and its cookie rule is not the ePrivacy rule. The revised FADP is a transparency-first regime, and the cookie provision lives in telecommunications law with an information-and-refusal standard rather than prior consent.
Law: Revised FADP (in force 1 September 2023); TCA Art. 45c
Privacy Act (Australia)
Australia has no general cookie-specific prior-consent rule. It has notice, necessity and direct-marketing obligations under the Australian Privacy Principles, alongside a continuing reform programme whose second tranche was released as draft legislation for consultation in August 2026.
Law: Privacy Act 1988 and the Australian Privacy Principles
APPI (Japan)
Japan took an unusual route. Rather than regulating cookies as personal data, the 2020 amendment created a category for data that only becomes identifying in the recipient’s hands, which is precisely what an advertising identifier is.
Law: Act on the Protection of Personal Information
PIPA (South Korea)
PIPA Article 15 provides several grounds for processing personal information. Where a controller relies on consent, the information and separation requirements are strict, and the PIPC has brought fact-specific enforcement actions involving behavioural advertising.
Law: Personal Information Protection Act
Start with your own site
A free scan names what is loading before anyone has chosen anything.