दुनिया भर के डेटा एन्क्रिप्शन नियम 2026 में
2026 में दुनिया भर के प्रमुख क्षेत्रों में डेटा एन्क्रिप्शन नियमों और अनुपालन आवश्यकताओं का एक व्यापक अवलोकन।
2026 में encryption rules jurisdiction के अनुसार sharply differ करते हैं। EU "appropriate technical measures" require करता है (GDPR Article 32), जिसमें AES-256 widely accepted baseline है। US sector-specific rules layer करता है: health के लिए HIPAA, payments के लिए PCI DSS 4.0, finance के लिए GLBA Safeguards Rule, plus CCPA/CPRA की अगुवाई में state laws का patchwork। China का PIPL (Articles 38-43) cross-border transfers पर export controls लगाता है। भारत का DPDPA (2023) 2025 में effect में आया। Brazil का LGPD GDPR को mirror करता है। कई jurisdictions — UK, Australia, France — ने lawful-access requirements introduce किए हैं जो end-to-end encryption से conflict करते हैं।
European Union: GDPR ने Global Template Set किया
GDPR Article 32 "personal data के pseudonymisation और encryption" को appropriate security measure के रूप में require करता है। यह strictly mandatory नहीं लेकिन functionally है — Article 34(3)(a) breach-notification requirements waive करता है जब data encryption से "unintelligible" render हुआ हो। European Data Protection Board guidance 01/2021 AES-256 या equivalent को expected minimum clarify करता है।
Article 44 और Chapter V EEA के बाहर transfers restrict करते हैं। Schrems II (C-311/18) के बाद, Standard Contractual Clauses को supplementary measures require करते हैं — typically end-to-end encryption जहाँ recipient keys control करे, ताकि US providers technically FISA 702 requests के तहत plaintext access न कर सकें। 2023 EU-US Data Privacy Framework ने कुछ cross-Atlantic flows restore किए लेकिन fragile legal ground पर है।
NIS2 Directive (October 2024 से effective) essential services के medium और large operators — energy, transport, health, digital infrastructure — तक similar encryption expectations extend करती है।
United States: Sector by Sector
US में uniform encryption requirements वाला कोई federal data-protection law नहीं है। बजाय:
- HIPAA Security Rule (45 CFR 164.312(a)(2)(iv) और (e)(2)(ii)): ePHI का encryption "addressable" है, meaning required है जब तक covered entity document न करे क्यों नहीं। Practice में, OCR audits इसे mandatory मानते हैं।
- PCI DSS 4.0 (March 2025 full enforcement): Requirement 3.5.1 PAN को unreadable render करने mandate करता है, Requirement 4.2.1 open networks पर strong cryptography require करता है (TLS 1.2 minimum, 1.3 preferred)।
- GLBA Safeguards Rule (16 CFR Part 314), 2023 updated: transit और at rest में customer information का encryption, financial institutions के लिए specific penalties।
- SEC Regulation S-P amendments (2024): broker-dealers और advisers के लिए 30 days में breach notification।
फिर state layer: CCPA/CPRA (California), CDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), plus 2026 में 14 और states के active laws। अधिकांश "reasonable security" cite करते हैं — जिसे plaintiffs' attorneys "आपने encrypt नहीं किया, इसलिए आप fail हुए" interpret करते हैं।
United Kingdom: UK GDPR Plus Investigatory Powers
UK GDPR, EU GDPR के Article 32 को mirror करता है। Twist है Investigatory Powers Act 2016 जो 2024 में amended हुआ, जो Home Office को Technical Capability Notices issue करने permit करता है जो providers को communications से "electronic protection" remove करने require करते हैं। यह E2EE के साथ uncomfortably बैठता है — Apple ने early 2025 में UK users से iCloud Advanced Data Protection temporarily withdraw किया — एक case जो litigation में है।
China: PIPL और Cryptography Law
Personal Information Protection Law (PIPL), November 2021 से effective, cross-border data transfers के लिए Articles 38-43 के ज़रिए strict encryption requirements impose करता है। China का Cryptography Law (2020) algorithms को "core," "common," और "commercial" categorize करता है — commercial cryptography, जिसमें most business file-transfer encryption शामिल है, China में बेचे जाने वाले products के लिए type certification require करता है। SM2, SM3 और SM4 (Chinese national algorithms) certain government और critical infrastructure use cases के लिए mandated हैं।
India: DPDPA आया
Digital Personal Data Protection Act (DPDPA), August 2023 में enacted और 2025 rules के ज़रिए operationalized, "reasonable security safeguards" (Section 8(5)) require करता है। January 2025 में released draft rules encryption को baseline expectation के रूप में specify करते हैं। Cross-border transfers permitted हैं सिवाय उन countries के जिन्हें government specifically block करे — GDPR के general prohibition से different "whitelist-but-open" approach।
DPDP Act भारतीय businesses के लिए particularly relevant है: file transfer services को यह ensure करना होगा कि personal data adequate encryption के साथ transmit और stored हो, और data fiduciaries data breach की स्थिति में Data Protection Board को notify करने के लिए bound हैं।
Brazil, Canada, Australia
Brazil का LGPD (Law 13.709/2018) GDPR closely parallel करता है, ANPD guidance encryption को expected Article 46 safeguard मानता है। Canada का PIPEDA "sensitivity के appropriate safeguards" require करता है — case law और OPC guidance most regulated data के लिए encryption establish करते हैं। Quebec का Law 25 (September 2024 से fully effective) explicit breach-notification और cross-border rules add करता है।
Australia का Privacy Act 1988 active reform में है; 2024 amendments ने privacy के लिए statutory tort introduce किया। Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 compelled technical assistance permit करता है जो effectively E2EE तोड़ता है — UK की तरह, एक live tension।
Jurisdiction Snapshot
| Region | Primary law | Encryption stance | Cross-border rule | |---|---|---|---| | EU | GDPR Art 32 | AES-256 expected | Chapter V / SCCs | | US Health | HIPAA 164.312 | Addressable = required | N/A | | US Payments | PCI DSS 4.0 | Required 3.5.1 | N/A | | UK | UK GDPR + IPA | Required; lawful-access tension | Adequacy decisions | | China | PIPL + Crypto Law | Required; SM algos for gov | Security assessment | | India | DPDPA 2023 | Reasonable safeguards | Blacklist model | | Brazil | LGPD | Expected Art 46 | ANPD oversight | | Canada | PIPEDA / Law 25 | Required in practice | Quebec explicit | | Australia | Privacy Act 1988 | Expected; AAA tension | Case-by-case |
Lawful-Access की समस्या
UK का IPA 2016, Australia का AAA 2018, और France का Projet de Loi Narcotrafic (2025 में introduced) सभी में provisions हैं जो providers को lawful order पर communications decrypt करने require करते हैं। यह GDPR की unintelligible data requirement और E2EE systems — जहाँ providers physically decrypt नहीं कर सकते — से टकराता है। यह conflict कैसे resolve होता है — technical workarounds, jurisdictional arbitrage, या genuine legal change के ज़रिए — यह 2026 का defining cryptography-policy question है।
यह व्यवहार में क्या मतलब रखता है
Multinational small या mid-size business के लिए, practical path है: at rest पर AES-256-GCM से और in transit पर TLS 1.3 से सब कुछ encrypt करें, keys ऐसे jurisdiction में रखें जिस पर trust हो, हर processor के साथ DPAs sign करें, और ऐसे file-transfer और email providers choose करें जो अपनी cryptographic architecture और subpoena response policies publish करते हों। Compliance एक "सही" regulation choose करने के बारे में नहीं है — यह सबसे strict applicable regime के तहत defensible posture बनाने के बारे में है।
File-transfer piece के लिए: hexatransfer.com पर आज़माएं — मुफ्त, बिना अकाउंट, 10 GB तक।
एंड-टू-एंड एन्क्रिप्शन के साथ बड़ी फ़ाइलें सुरक्षित रूप से भेजें
एंड-टू-एंड एन्क्रिप्शन के साथ 10 GB तक की फ़ाइलें मुफ़्त में ट्रांसफ़र करें। अकाउंट की आवश्यकता नहीं। अपलोड से पहले आपकी फ़ाइलें ब्राउज़र में एन्क्रिप्ट की जाती हैं — कोई और उन्हें पढ़ नहीं सकता।
फ़ाइल भेजें