Skip to content
HexaTransfer
Back to blog
Encryption & Security

Data Encryption Regulations Around the World in 2026

A comprehensive overview of data encryption regulations and compliance requirements across major jurisdictions worldwide in 2026.

Encryption rules in 2026 differ sharply by jurisdiction. The EU requires "appropriate technical measures" (GDPR Article 32), with AES-256 widely accepted as the baseline. The US layers sector-specific rules: HIPAA for health, PCI DSS 4.0 for payments, GLBA Safeguards Rule for finance, plus a patchwork of state laws led by CCPA/CPRA. China's PIPL (Articles 38-43) imposes export controls on cross-border transfers. India's DPDPA (2023) took effect in 2025. Brazil's LGPD mirrors GDPR. Several jurisdictions — UK, Australia, France — have introduced lawful-access requirements that conflict with end-to-end encryption.

European Union: GDPR Sets the Global Template

GDPR Article 32 requires "pseudonymisation and encryption of personal data" as an appropriate security measure. It's not strictly mandatory but functionally so — Article 34(3)(a) waives breach-notification requirements when data was rendered "unintelligible" through encryption. The European Data Protection Board guidance 01/2021 clarifies AES-256 or equivalent as the expected minimum.

Article 44 and Chapter V restrict transfers outside the EEA. After Schrems II (C-311/18), Standard Contractual Clauses require supplementary measures — typically end-to-end encryption where the recipient controls the keys, so US providers can't technically access plaintext under FISA 702 requests. The 2023 EU-US Data Privacy Framework restored some cross-Atlantic flows but sits on fragile legal ground.

The NIS2 Directive (effective October 2024) extends similar encryption expectations to medium and large operators of essential services — energy, transport, health, digital infrastructure.

United States: Sector by Sector

There's no federal US data-protection law with uniform encryption requirements. Instead:

  • HIPAA Security Rule (45 CFR 164.312(a)(2)(iv) and (e)(2)(ii)): encryption of ePHI is "addressable," meaning required unless the covered entity documents why not. In practice, OCR audits treat it as mandatory.
  • PCI DSS 4.0 (March 2025 full enforcement): Requirement 3.5.1 mandates rendering PAN unreadable, Requirement 4.2.1 requires strong cryptography over open networks (TLS 1.2 minimum, 1.3 preferred).
  • GLBA Safeguards Rule (16 CFR Part 314), updated 2023: encryption of customer information in transit and at rest, with specific penalties for financial institutions.
  • SEC Regulation S-P amendments (2024): breach notification within 30 days for broker-dealers and advisers.

Then the state layer: CCPA/CPRA (California), CDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), plus 14 more states with active laws in 2026. Most cite "reasonable security" — which plaintiffs' attorneys interpret as "you didn't encrypt, so you failed."

United Kingdom: UK GDPR Plus Investigatory Powers

UK GDPR mirrors EU GDPR's Article 32. The twist is the Investigatory Powers Act 2016 as amended in 2024, which permits the Home Office to issue Technical Capability Notices requiring providers to remove "electronic protection" from communications. This sits uneasily with E2EE — Apple temporarily withdrew iCloud Advanced Data Protection from UK users in early 2025 in response, a case that remains in litigation.

China: PIPL and Cryptography Law

The Personal Information Protection Law (PIPL), effective November 2021, imposes strict encryption requirements through Articles 38-43 for cross-border data transfers. China's Cryptography Law (2020) categorizes algorithms as "core," "common," and "commercial" — commercial cryptography, which includes most business file-transfer encryption, requires type certification for products sold in China. SM2, SM3, and SM4 (Chinese national algorithms) are mandated for certain government and critical infrastructure use cases.

India: DPDPA Arrives

The Digital Personal Data Protection Act (DPDPA), enacted August 2023 and operationalized through 2025 rules, requires "reasonable security safeguards" (Section 8(5)). The draft rules released in January 2025 specify encryption as a baseline expectation. Cross-border transfers are permitted except to countries specifically blocked by the government — a "whitelist-but-open" approach different from GDPR's general prohibition.

Brazil, Canada, Australia

Brazil's LGPD (Law 13.709/2018) parallels GDPR closely, with ANPD guidance treating encryption as an expected Article 46 safeguard. Canada's PIPEDA requires "safeguards appropriate to the sensitivity" — case law and OPC guidance establish encryption for most regulated data. Quebec's Law 25 (fully effective September 2024) adds explicit breach-notification and cross-border rules.

Australia's Privacy Act 1988 is under active reform; the 2024 amendments introduced a statutory tort for privacy. The Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 permits compelled technical assistance that effectively breaks E2EE — like the UK, a live tension.

Jurisdiction Snapshot

| Region | Primary law | Encryption stance | Cross-border rule | |---|---|---|---| | EU | GDPR Art 32 | AES-256 expected | Chapter V / SCCs | | US Health | HIPAA 164.312 | Addressable = required | N/A | | US Payments | PCI DSS 4.0 | Required 3.5.1 | N/A | | UK | UK GDPR + IPA | Required; lawful-access tension | Adequacy decisions | | China | PIPL + Crypto Law | Required; SM algos for gov | Security assessment | | India | DPDPA | Reasonable safeguards | Blacklist model | | Brazil | LGPD | Expected Art 46 | ANPD oversight | | Canada | PIPEDA / Law 25 | Required in practice | Quebec explicit | | Australia | Privacy Act 1988 | Expected; AAA tension | Case-by-case |

The Lawful-Access Problem

The UK's IPA 2016, Australia's AAA 2018, and France's Projet de Loi Narcotrafic (introduced 2025) all contain provisions requiring providers to decrypt communications on lawful order. This collides with GDPR's requirement for unintelligible data and with E2EE systems where providers physically cannot decrypt. How this conflict resolves — whether through technical workarounds, jurisdictional arbitrage, or genuine legal change — is the defining cryptography-policy question of 2026.

What This Means in Practice

For a multinational small or mid-size business, the practical path is: encrypt everything with AES-256-GCM at rest and TLS 1.3 in transit, keep keys in a jurisdiction you trust, sign DPAs with every processor, and pick file-transfer and email providers that publish their cryptographic architecture and their subpoena response policies. Compliance isn't about picking the one "correct" regulation — it's about building a posture defensible under the strictest applicable regime.

For the file-transfer piece: try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file