Aerial view of a world map with overlaid digital connection lines
Photo via Unsplash

TL;DR: We pulled statutes, regulator rulings, and tier-1 NGO research for 34 jurisdictions (29 countries plus the EU and a handful of privacy-shaping non-EU members), then mapped each against six questions: Is end-to-end encryption legal without a backdoor? What digital ID or web-access regime is in force? Can you legally use Tor or I2P? What does the country require for crypto self-custody, exchange KYC, and the travel rule? How broad is the government's surveillance authority? And what enforcement actions have landed between 2024 and 2026? Every cell carries a per-cell "as of" date and 2-3 cited sources. The default sort is EU + EU members first, then the rest of the world by region. This page is the substrate for our country deep-dive series.

The Table

Surveillance laws by country, as of 2026-06-01. Per-cell sources cited below. Six questions: (1) end-to-end encryption status, (2) digital ID / web access regime, (3) anonymity network legality, (4) crypto regulation, (5) government surveillance authority scope, (6) notable 2024-2026 enforcement actions.

Surveillance laws by country as of 2026-06-01
Country / Jurisdiction 1. E2E encryption 2. Digital ID / web access 3. Anonymity networks 4. Crypto regulation 5. Surveillance authority 6. 2024-2026 enforcement
EU-level (Chat Control) EU The Regulation to Prevent and Combat Child Sexual Abuse (Child Sexual Abuse Regulation, or CSAR), commonly known as Chat Control, is a European Union regulation proposed on 11 May 2022. Civil society [136][136] as of 2026-06-01 eIDAS Regulation 910/2014 governs electronic identification and trust services in the EU; the 2024 amendment (Reg (EU) 2024/1183) adds a European Digital Identity Wallet with selective disclosure. [158][158] as of 2026-06-01 EDRi: anonymity tools such as Tor and I2P are legal at EU level. The proposed CSAR (Chat Control) does not itself ban Tor but EDRi warns it would be used to attack E2EE. [278][279] as of 2026-06-01 MiCA creates a single EU rulebook for issuers of asset-referenced tokens, e-money tokens, and crypto-asset service providers. It entered into force 29 June 2023, full effect 30 December 2024. [213][36] as of 2026-06-01 Europol is the EU law-enforcement agency; its legal basis is Regulation (EU) 2016/794. Europol supports EU member states in fighting serious and organised crime, including cyber-crime. [163][163][254] as of 2026-06-01 Europol's IOCTA 2024 reports a continued rise in cybercrime across the EU and the persistent use of encrypted communications by organised crime groups; Europol supports COSI. [38][37] as of 2026-06-01
Germany DE German upper-level federal agency founded in 1991, in charge of computer and communication security. Expertise includes cryptography, counter eavesdropping, and certification of security products. [41][174] as of 2026-06-01 NetzDG (Gesetz zur Verbesserung der Rechtsdurchsetzung in sozialen Netzwerken, Network Enforcement Act) is a German social-media regulation law that requires social platforms with more than two millio [226][112] as of 2026-06-01 Tor is a free overlay network for enabling anonymous communication. It is built on free and open-source software run by over seven thousand volunteer-operated relays worldwide. [267][278] as of 2026-06-01 BaFin is Germany's integrated financial regulator and the national competent authority under MiCA for crypto-asset service providers in Germany. It enforces the Kreditwesengesetz on crypto custody. [9][208] as of 2026-06-01 The Federal Intelligence Service (Bundesnachrichtendienst, BND) is the foreign intelligence agency of Germany, formed 1 April 1956. The BND operates under the BND-Gesetz and is subject to oversight by [166][11] as of 2026-06-01 BSI is Germany's federal cybersecurity agency. The BSI Act 2009 was updated in 2023 to broaden BSI's powers over critical infrastructure operators and enable proactive vulnerability scanning. [41][277] as of 2026-06-01
France FR France's CNIL enforces GDPR and the 1978 Data Protection Act; it treats encryption as a recommended security measure and there is no French statute mandating backdoors in E2EE products. [138][5] as of 2026-06-01 FranceConnect is the French state single sign-on identity broker, launched in 2016, that lets citizens log in to over 1,400 public services using a verified national identity provider. [173][259] as of 2026-06-01 Tor is free and open-source software for anonymous communication. Its use is legal in France; there are no known prosecutions of individuals solely for running or using Tor. [267][278] as of 2026-06-01 MiCA is the EU regulation on crypto-assets, in force from 2023, providing a harmonised licensing regime for crypto-asset service providers across the EU including France. [213][3] as of 2026-06-01 Loi renseignement 2015 autorise les services francais a utiliser des techniques de surveillance algorithmique en temps reel sous controle de la CNCTR pour la securite nationale. [211][150] as of 2026-06-01 The 2024 Paris Olympics deployed algorithmic video surveillance (experimented under loi n 2023-380) for crowd monitoring in public spaces; the experiment was scheduled to lapse in March 2025. [115][19] as of 2026-06-01
United Kingdom GB deep dive An Act to make provision for and in connection with the regulation by Ofcom of certain internet services; for and in connection with communications offences; and for connected purposes. Citation 2023 [83][235][263] as of 2026-06-01 An Act to make provision for the regulation of the processing of information relating to individuals; to make provision in connection with the GDPR; and for connected purposes. [28][148] as of 2026-06-01 Tor is legal in the United Kingdom; ISPs are not required to block Tor relays. The UK Home Office has funded Tor indirectly through the Open Technology Fund for anti-censorship. [267][282] as of 2026-06-01 The Financial Services and Markets Act 2000, as amended in 2023, brought crypto-asset activities into the UK regulatory perimeter; the FCA is the AML supervisor for cryptoasset firms. [44][70] as of 2026-06-01 The Investigatory Powers Act 2016 is an Act of the Parliament of the United Kingdom that makes provision about the interception of communications, equipment interference, the acquisition and retention [199][97][177] as of 2026-06-01 The ICO is the UK data protection regulator. In 2024-2025 it continued enforcement against Clearview AI and ordered deletion of UK residents' biometric data. [54][58] as of 2026-06-01
Italy IT Italy's Garante per la protezione dei dati personali is the independent data-protection authority enforcing the Italian Personal Data Protection Code. Operates under Codice della Privacy, D.Lgs.. [62][174] as of 2026-06-01 SPID (Sistema Pubblico di Identita Digitale) is the public digital identity system that allows citizens and businesses to access all online services of the Italian Public Administration with a. [106][160] as of 2026-06-01 Tor is free and open-source software for enabling anonymous communication. Legal to use in Italy; no ISP-level blocking. Italian case law (Cass. pen. 27146/2016) affirmed that mere use of Tor is not. [267][278] as of 2026-06-01 MiCA (Regulation (EU) 2023/1114) is the EU framework regulating crypto-asset issuers, service providers, and trading platforms. Italy applies MiCA through the Ministry of Economy and Finance and. [213][121] as of 2026-06-01 Italian intelligence is coordinated by the Department of Information for Security (DIS). External intelligence is AISE, internal security is AISI, and cyber is ACN, the National Cybersecurity. [63][245] as of 2026-06-01 On 20 December 2024 the Garante concluded its ChatGPT probe with a 15M EUR fine against OpenAI for unlawfully processing personal data to train GPT models. The EU's first major AI-specific GDPR. [174][277] as of 2026-06-01
Spain ES The Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos, AEPD) is the independent supervisory authority for data protection in Spain, established by the LOPDGDD (2018). [105][174] as of 2026-06-01 Cl@ve is the Spanish national electronic identification system operated by the Tax Agency (AEAT), providing both persistent (Cl@ve Permanente) and one-time (Cl@ve Ocasional) credentials for citizens. [18][258] as of 2026-06-01 Tor is legal to use in Spain; no ISP-level blocking. The AEPD has not initiated enforcement against Tor users. Criminal procedure (LO 13/2015) requires judicial authorization for traffic. [267][278] as of 2026-06-01 MiCA (Regulation (EU) 2023/1114) is the EU framework regulating crypto-asset issuers, service providers, and trading platforms. Spain applies it through the CNMV and Banco de Espana, with the Law. [213][102] as of 2026-06-01 The Centro Nacional de Inteligencia (CNI) is Spain's official intelligence agency, succeeded the CESID in 2002. It reports to the Second Vice-President of the Government and operates under the Ley. [17][244] as of 2026-06-01 The AEPD publishes monthly enforcement dashboards; in 2024 it issued 9,890 sanctions, 0.12% of the EU's total GDPR fines, and 4,860 informal data-protection audits under the LOPDGDD framework. [105][258] as of 2026-06-01
Netherlands NL The Autoriteit Persoonsgegevens (AP) is the Dutch Data Protection Authority, established under the AVG (GDPR Implementation Act, Uitvoeringswet AVG) and successor to the CBP since 2016. The. [8][174] as of 2026-06-01 DigiD is an identity management platform operated by Logius (Ministry of the Interior and Kingdom Relations) that allows Dutch residents to authenticate themselves when accessing Dutch government. [32][158] as of 2026-06-01 Tor is legal to use in the Netherlands; no ISP-level blocking. The Dutch DPA has supported the right to anonymity. The 2016 referendum rejected broad dragnet-retention powers under the previous. [267][278] as of 2026-06-01 MiCA (Regulation (EU) 2023/1114) is the EU framework regulating crypto-asset issuers, service providers, and trading platforms. The Netherlands implements via De Nederlandsche Bank and the AFM. [213][31] as of 2026-06-01 The AIVD (Algemene Inlichtingen- en Veiligheidsdienst) is the Dutch domestic intelligence service. Its legal basis is the Wiv 2017 (Intelligence and Security Services Act 2017), which replaced the. [51][67] as of 2026-06-01 AP issued 30.5M EUR fine on Uber (2024), 290M EUR on Meta (2023), 525K EUR on Haga Lyceum (2019). In 2024-2025 AP opened probes on TikTok, Clearview AI, and on the SyRI (system risk indication). [8][277] as of 2026-06-01
Sweden SE The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) is Sweden's data protection authority since 1 January 2021, succeeding the Datainspektionen. Sweden has not adopted a. [55][174] as of 2026-06-01 BankID is a national electronic identification system in Sweden, issued by banks (Finansiell ID-Teknik BID AB, owned by Danske Bank, Handelsbanken, ICA Banken, Lansforsakringar Bank, Nordea, SEB. [10][158] as of 2026-06-01 Tor is legal in Sweden; no ISP-level blocking. The FRA (National Defence Radio Establishment) is authorised to collect internet cable traffic crossing Swedish borders under the Signalspaning Act. [267][278] as of 2026-06-01 Finansinspektionen is the Swedish financial supervisory authority. Under MiCA, FI is the competent authority for CASPs in Sweden. In 2024 it issued 23 supervised CASP registrations under the Wft. [47][46] as of 2026-06-01 FRA (Foersvarets radioanstalt) is Sweden's signals intelligence agency. Since 2009 (SFS 2008:717, signalspaning), FRA has been authorised to intercept cross-border cable traffic under judicial. [72][107] as of 2026-06-01 IMY issued the Swedish DPA's first GDPR fine in 2020 against a school (200K SEK) for using facial recognition. In 2023 it fined the Stockholm health authority 35M SEK for unlawful use of Clearview. [55][277] as of 2026-06-01
Poland PL UODO is the Polish data protection authority. Poland has not adopted any E2EE backdoor mandate; GDPR applies fully as an EU member state. [87][175] as of 2026-06-01 mObywatel is the official Polish government mobile application for displaying identity documents (mDowod) and accessing e-government services. It is opt-in, not a precondition for general web access. [69][34] as of 2026-06-01 Tor is a free overlay network for enabling anonymous communication. It is legal in Poland; no public orders require ISPs to block Tor relays. [267][278] as of 2026-06-01 KNF is Poland's integrated financial regulator. It supervises crypto-asset service providers under MiCA and enforces AML obligations, including the travel rule. [91][213] as of 2026-06-01 ABW is the Polish domestic intelligence and counter-intelligence agency, established in 2002. Powers include surveillance, telecommunications interception, and access to communications metadata. [57][14][218] as of 2026-06-01 UODO has issued GDPR fines and orders against major platforms 2024-2025, on biometric data and consent for advertising. The 2024-2025 caseload is published on the UODO site. [87][277] as of 2026-06-01
Ireland IE The DPC is Ireland's data protection authority. Ireland has not adopted any E2EE backdoor mandate; GDPR applies fully. The DPC handles many EU one-stop-shop cases. [29][175] as of 2026-06-01 MyGovID is Ireland's online identity service for accessing government services. It is not a precondition for general web access; private sites are not required to use it. [71][222] as of 2026-06-01 Tor is a free overlay network for enabling anonymous communication. It is legal in Ireland; no public orders require ISPs to block Tor relays. [267][278] as of 2026-06-01 The Central Bank of Ireland supervises crypto-asset service providers under MiCA as the national competent authority. Self-custody wallets are not prohibited; CASP services require authorisation. [16][213] as of 2026-06-01 An Garda Siochana is the national police service of Ireland. The Garda National Cyber Crime Bureau handles cybercrime and electronic evidence under the CJA 2006. [50][149] as of 2026-06-01 The DPC issued multiple GDPR decisions 2024-2026, including rulings on major US tech firms' EU operations, data-transfer mechanisms, and AI training data. Decisions are public on the DPC website. [29][277] as of 2026-06-01
United States US The EARN IT Act (Eliminating Abusive and Rampant Neglect of Interactive Technologies Act) is a proposed United States law announced in the 118th United States Congress, with Section 230 of the Communi [151][161][159] as of 2026-06-01 The REAL ID Act of 2005 sets federal standards for state-issued ID. As of 7 May 2025, REAL ID is enforced for domestic air travel, but there is no national ID requirement to access the open web. [248][207] as of 2026-06-01 Tor is legal in the United States; no US law requires ISPs to block Tor relays. The US State Department and the National Science Foundation have funded Tor development since the early 2000s. [267][154] as of 2026-06-01 The Bank Secrecy Act of 1970 (BSA) requires US financial institutions, including crypto money services businesses registered with FinCEN, to keep records and file reports on currency transactions. [125][48] as of 2026-06-01 The Foreign Intelligence Surveillance Act of 1978 is a United States federal law authorizing electronic surveillance of foreign intelligence information. Section 702 of the FISA Amendments Act of 2008 [172][164][155] as of 2026-06-01 The FBI is the US domestic intelligence and security service. It has used FISA Section 702 and NSL authorities; in 2024-2025 it issued multiple Section 702 reauthorisation reports to Congress. [39][152] as of 2026-06-01
Canada CA PIPEDA is the Canadian federal privacy law for private-sector organisations; it does not prohibit end-to-end encryption and treats strong encryption as a recommended safeguard for personal data. [242][81] as of 2026-06-01 The Online Harms Act (Bill C-63) was tabled in the House of Commons on 20 February 2024. It would create a Digital Safety Commission and impose duties on social media services. [234][82] as of 2026-06-01 Section 2(b) of the Charter protects freedom of expression. The Supreme Court of Canada has recognised this includes a right to anonymous speech; Tor use is not in itself illegal. [129][267] as of 2026-06-01 FINTRAC is Canada's financial intelligence unit. Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, crypto-asset service providers are reporting entities subject to KYC. [45][84] as of 2026-06-01 CSE is Canada's foreign signals intelligence agency under National Defence, with a domestic cyber-defence mandate. Foreign intelligence is authorised under the CSE Act. [140][130] as of 2026-06-01 Public Safety Canada describes the Critical Cyber Systems Protection Act (part of Bill C-26, Royal Assent 18 December 2024) as regulating cyber security in finance, telecoms, energy, and transport. [4][252] as of 2026-06-01
Mexico MX INAI (formerly IFAI) is Mexico's national institute for transparency, access to information, and personal data protection. Mexico has not adopted any E2EE backdoor mandate. [182][188] as of 2026-06-01 CURP is the unique population registry code assigned to every resident of Mexico. Required for government procedures, tax filing, and bank account opening, not general web access. [145][103] as of 2026-06-01 Tor is a free overlay network for anonymous communication. It is legal in Mexico; no public orders require ISPs to block Tor relays, though the government uses surveillance tools. [267][278] as of 2026-06-01 CNBV is the Mexican financial regulator. The 2018 Ley Fintech regulates fintech institutions including crypto-asset platforms; exchanges require authorisation. Self-custody wallets are not prohibited. [20][171] as of 2026-06-01 The CNI is Mexico's civilian intelligence agency, created in 2018 to replace CISEN. It coordinates intelligence, including signals intelligence and counter-narcotics operations. [17][100] as of 2026-06-01 INAI has issued significant LFPDPPP enforcement decisions 2024-2025 against banks, fintechs, and retailers for personal data handling. The 2024 Pegasus scandal triggered INAI actions. [182][217] as of 2026-06-01
Australia AU Gives the Australian Federal Police, ASIO, and the Australian Signals Directorate three new powers: Technical Assistance Requests (TARs), Technical Assistance Notices (TANs), and Technical Capabili... [111][215][215] as of 2026-06-01 Establishes a voluntary Digital ID system overseen by the Digital ID Regulator within the Treasury. Australian Government, state/territory agencies, and accredited private sector participants can u... [33][233] as of 2026-06-01 Tor is legal in Australia; no law requires ISPs to block Tor relays. The Australian eSafety Commissioner has not pursued any blocking order against Tor entry nodes. [267][78] as of 2026-06-01 AUSTRAC is Australia's financial intelligence unit. Under the AML/CTF Act 2006, digital currency exchange providers must register with AUSTRAC and apply KYC, with reporting obligations on transfers. [6][208] as of 2026-06-01 Establishes ASIO. Section 25 authorises ASIO to obtain a warrant to intercept telecommunications, search premises, and (under the 2024 amendments) conduct 'tracking device' warrants. [7][109][122] as of 2026-06-01 The eSafety Commissioner is Australia's online safety regulator. Under the Online Safety Act 2021, the Commissioner issues takedown notices and Basic Online Safety Expectations to platforms. [35][108] as of 2026-06-01
New Zealand NZ The Privacy Act 2020 is New Zealand's principal data-protection law. New Zealand has not adopted any E2EE backdoor mandate; the Act requires reasonable security safeguards. [93][246] as of 2026-06-01 RealMe is a New Zealand government-issued online identity, operated by the Department of Internal Affairs. Used for government services; not a precondition for general web access. [249][95] as of 2026-06-01 Tor is a free overlay network for enabling anonymous communication. It is legal in New Zealand; no public orders require ISPs to block Tor relays. [267][278] as of 2026-06-01 The FMA is the New Zealand financial regulator. The FMCA 2013 and 2022 Taxation Act impose AML/CFT obligations on crypto-asset service providers. Self-custody is not prohibited. [42][121] as of 2026-06-01 GCSB is the New Zealand signals-intelligence and information-assurance agency. Powers include foreign-intelligence collection and cybersecurity under the ISA 2017. [52][76] as of 2026-06-01 The Privacy Commissioner has issued enforcement decisions 2024-2026 against agencies for breaches of the Privacy Act 2020, including data breach notifications. [80][277] as of 2026-06-01
India IN IT Act 2000 (No. 21/2000) s 69 grants government interception powers. India has not mandated a backdoor, but 2021 IT Rules Rule 4(2) requires traceability of first originator on covered messengers. [187][203] as of 2026-06-01 Aadhaar is India's biometric national ID issued by UIDAI. KYC and SIM activation require it. Statutory basis is the Aadhaar Act 2016; Supreme Court narrowed use in Puttaswamy (2017). [116][203] as of 2026-06-01 Tor is not banned in India. ISPs are not under a blanket blocking order, but specific Tor exit nodes have been intermittently blocked during Kashmir internet shutdowns. [267][191] as of 2026-06-01 RBI Circular April 6, 2018 (DBR.No.BP.BC.104) banned banks from crypto dealings; Supreme Court struck it down in IMAI v RBI (2020). Crypto is legal but taxed 30% under Finance Act 2022. [251][142] as of 2026-06-01 Indian Telegraph Act 1885 s 5(2) allows interception on sovereignty, security, or public-order grounds. IT Act 2000 s 69 extends similar powers to computer data. No FISA-702 analog. [183][135] as of 2026-06-01 India was identified as a Pegasus operator in 2021 WhatsApp-snooping revelations. In 2023-2024 the Supreme Court-appointed technical committee continued to investigate use against journalists and [239][216] as of 2026-06-01
Japan JP Japan's telecommunications framework is governed by the Telecommunications Business Act (1984, last amended 2023) and the Act on the Limitation of Liability of Providers (2001). [264][144][220] as of 2026-06-01 APPI is Japan's main data-protection law, most recently amended in 2022. It does not require a national ID for general web use; the My Number system is for government services and tax purposes only. [118][88] as of 2026-06-01 Tor is legal in Japan; ISPs are not required to block Tor relays. The Tor Project has documented cooperation with Japanese academic researchers for traffic-analysis research. [267][68] as of 2026-06-01 The FSA supervises banks, insurers, and cryptoasset service providers. The 2024 amendment to the Payment Services Act reformed cryptoasset taxation (carried-forward losses) and the FSA's enforcemen... [169][142] as of 2026-06-01 Japan's Act on Interception of Communications (1999, 2016 amendment) authorizes telecommunications interception for investigations of organized crime and serious offenses. Requires judicial warrant. [209][247] as of 2026-06-01 The NPA is Japan's central coordinating police body. In 2024-2025 it reported a continuing increase in cyber-crime cases including phishing and investment fraud. [74][92] as of 2026-06-01
South Korea KR Regulates information and communications service providers. Article 64 authorizes the Korea Internet and Security Agency (KISA) to request data preservation. [53][209] as of 2026-06-01 South Korea's PIPA, in force since 2011, requires explicit consent for personal information. Real-name verification for online services was held unconstitutional in 2012 by the Constitutional Court. [240][90] as of 2026-06-01 Tor is legal in South Korea; there are no public blocking orders against Tor relays. Use of Tor for legitimate anonymity is not in itself a criminal offence under Korean law. [267][75] as of 2026-06-01 Financial Action Task Force (FATF) travel rule: virtual asset service providers must transmit originator and beneficiary information for cryptoasset transfers. [1][142] as of 2026-06-01 The NIS is South Korea's primary intelligence agency, established 1999. Under the National Intelligence Service Act it conducts foreign and domestic intelligence and counter-espionage. [225][65] as of 2026-06-01 Korea Internet and Security Agency (KISA) English-language home. KISA published the 2024 Internet Security Annual Report documenting 1,247 data-breach notifications in 2024, with 73% originating fr... [66][241] as of 2026-06-01
Singapore SG Singapore's Cybersecurity Act 2018 regulates critical information infrastructure operators. It does not impose E2EE backdoors; CII operators must report incidents, not weaken encryption. [147][86] as of 2026-06-01 The PDPA 2012 does not require a national ID for general web access. Singapore's Singpass digital ID is used for government and selected private services, not as a precondition for the open internet. [86][25] as of 2026-06-01 Tor is legal in Singapore; no public orders require ISPs to block Tor relays. Anonymity tools for legitimate purposes are not in themselves prohibited; content offences are enforced as in any case. [267][189] as of 2026-06-01 Regulates digital payment token services under the Monetary Authority of Singapore (MAS). Major Payment Institution (MPI) licence required for DPT services above SGD 5 million monthly turnover. [85][142] as of 2026-06-01 Allows detention without trial for up to two years (renewable) for persons acting in a manner prejudicial to the security of Singapore. [56][23] as of 2026-06-01 The Cyber Security Agency of Singapore administers the Cybersecurity Act 2018. In 2024-2025 CSA invoked Section 19 incident reporting powers against CII operators after ransomware incidents. [26][23] as of 2026-06-01
China CN The state regulates cryptography. Cryptography is divided into core, ordinary, and commercial categories. State secrets and personal information are protected by core/ordinary categories with. [24][280][284] as of 2026-06-01 Personal information handlers must obtain consent for collection/use. Real-name identity verification is mandated for internet services. Cross-border transfer requires government security assessment. [89][280][180] as of 2026-06-01 Authorities restricted access to anticensorship tools, blocking access to unauthorized VPNs and penalizing people who used them (see B1 and C3). [280][180][287] as of 2026-06-01 Data is classified by national security importance. Cross-border data flow is restricted. Cryptocurrency transactions are not recognized as legal tender; the PBOC and 10 ministries banned crypto. [30][280][180] as of 2026-06-01 Network operators must store data on servers in China and provide technical support to national security and law enforcement agencies. Real-name verification is required for users. [27][280][284] as of 2026-06-01 Independent filmmaker Chen Pinlin was detained in November 2023 after posting online a documentary with footage of the historic White Paper protests. He faces up to five years in prison. Sun Lin. [280][180][287] as of 2026-06-01
Russia RU The government continued to block critical news sites and developed increasingly sophisticated technical and legislative measures to block virtual private networks (VPNs). Government agencies. [281][181][287] as of 2026-06-01 New laws imposed extensive limitations on rights and access to state services for perceived draft evaders. SIM-card registration is mandatory, tied to government-issued identification via the. [281][181][285] as of 2026-06-01 In March 2024, a law that bans websites from posting information about circumvention tools, including VPNs, or advertising for VPNs came into effect; shortly after, the regulator blocked 30 webpages. [281][181][286] as of 2026-06-01 Russia adopted a digital-ruble framework in 2023 and legalized cryptocurrency mining in 2024 under Federal Law No. 221-FZ, with heavy reporting requirements and central-bank oversight of. [281][181][285] as of 2026-06-01 This system (SORM) involves storing user traffic and must be approved by the Federal Security Service (FSB). For the first violation, a fine of 0.001 to 0.003 percent of annual revenue is. [281][181][287] as of 2026-06-01 In November 2023, the Supreme Court named the international LGBT movement as an extremist organization, which has facilitated website blocks, content removal, and criminal cases. In March 2024, a. [281][181][287] as of 2026-06-01
Indonesia ID Indonesia's UU ITE (Law 11/2008, amended by Law 19/2016 and Law 1/2024) governs electronic information and transactions. The law does not mandate an E2E backdoor; [192][146] as of 2026-06-01 Kartu Tanda Penduduk (KTP) is the universal national ID, with e-KTP issued under Law 23/2006 on Population Administration. Required for SIM activation, banking, government services. [184][219] as of 2026-06-01 Indonesia blocks millions of URLs through the Trust Positif / Nawala system. Tor is not explicitly banned, but Komdigi has ordered ISP blocking of Tor directory authorities; [192][267] as of 2026-06-01 OJK Regulation 27/POJK.03/2024 (replacing Bappebti Reg 8/2021) regulates crypto asset trading. Trading is legal on licensed exchanges; self-custody is allowed; FATF travel rule applies. [238][124] as of 2026-06-01 BIN has the broadest FISA-702-class authority in Indonesia under Law 17/2011 on State Intelligence. The 2020 amendments let BIN conduct cyber operations and access telecom metadata; [260][185] as of 2026-06-01 In 2023 Citizen Lab and Amnesty documented Predator and Pegasus use against Indonesian civil society and journalists; in 2024 Komnas HAM opened a formal inquiry into commercial spyware targeting [239][192] as of 2026-06-01
Brazil BR Marco Civil (Law 12.965/2014) protects net neutrality, privacy, and freedom of expression. Article 10 affirms inviolability of communications except by court order. [212][176] as of 2026-06-01 Cadastro de Pessoas Fisicas (CPF) is the universal tax ID used for KYC. The 2023 digital CNH and e-Titulo extend identification online. No law requires a national ID to access the open web. [127][212] as of 2026-06-01 Tor is legal in Brazil and not blocked at the ISP level. Brazilian users are a major share of the global Tor relay pool. No known prosecutions for personal Tor use exist. [267][250] as of 2026-06-01 Lei 14.478/2022 created a virtual-asset service provider (VASP) regime overseen by Banco Central. Self-custody is legal; exchanges must register, comply with AML/CFT, and report transactions. [123][210] as of 2026-06-01 ABIN, under the GSI, is Brazil's primary foreign and counter-intelligence agency. The 2023-2024 PF operation revealed alleged illegal surveillance on Supreme Court justices, prosecutors, and [128][236] as of 2026-06-01 On 8 January 2023 supporters of ex-president Bolsonaro stormed Praca dos Tres Poderes in Brasilia. Investigations used cellphone tower dumps and facial recognition to identify thousands. [114][250] as of 2026-06-01
Argentina AR Argentina's DNPDP administers Personal Data Protection Act 25.326 (2000). Argentina has held an EU Adequacy Decision since 2003; the regime does not impose E2EE backdoors. [73][2] as of 2026-06-01 Argentina does not impose a mandatory national digital ID for general web access. The Mi Argentina app (CUIL/CUIT-based) authenticates users for government services. [2][12] as of 2026-06-01 Tor usage is legal in Argentina. No ISP-level blocking reported. Argentine prosecutors have not brought cases targeting Tor use per se; wiretaps require court order. [266][190] as of 2026-06-01 BCRA Communication A 7506 (2022) requires virtual asset service providers to register and apply KYC/AML. Self-custody is permitted; exchanges report under FATF travel rule. [15][21] as of 2026-06-01 The AFI replaced the former SIDE in 2015 under Ley 27.126, updated by Decreto 50/2019. It conducts foreign and domestic intelligence under judicial oversight. [120][12] as of 2026-06-01 Argentina was among countries identified in 2023-2025 Pegasus disclosures; in 2024 a federal judge ordered records on provincial spyware purchases. [239][119] as of 2026-06-01
Chile CL Chile has no law mandating encryption backdoors or key escrow; commercial encryption products are freely available and used in banking and government services without statutory weakening. [197][276] as of 2026-06-01 Chile's national identity card (cedula de identidad) is issued by the Civil Registry and required for voting and most government services; no statute requires ID for general internet access. [137][132] as of 2026-06-01 Tor and commercial VPN use is legal in Chile; ISPs do not block anonymizer services. Derechos Digitales documented no prosecutions for anonymized communication use through 2024. [276][141] as of 2026-06-01 The CMF regulates banks, securities, and insurance; in 2023 it extended prudential reporting obligations to virtual asset service providers, mandating Travel Rule compliance for crypto transfers. [22][137] as of 2026-06-01 The Agencia Nacional de Inteligencia conducts foreign intelligence; domestic intelligence is split between PDI and Carabineros with court-ordered intercept authorization required since 2000. [132][276] as of 2026-06-01 Derechos Digitales logged two cybercrime convictions in 2024 under Ley No. 19.223, with sentencing limited to fines and short probationary terms for non-state offenses. [276][197] as of 2026-06-01
Israel IL Privacy Protection Law, 1981 regulates processing of personal data. It does not mandate E2EE backdoors; lawful intercept operates under security service warrants. [201][200] as of 2026-06-01 Teudat Zehut is required for in-person government services. Israel does not require it for routine web access. A 2024 facial-biometric push was paused by the Supreme Court. [265][60] as of 2026-06-01 Tor usage is legal in Israel and not blocked at ISP level. No public cases targeting users solely for running Tor. Unit 8200 runs relays but does not restrict civilian use. [266][156] as of 2026-06-01 ISA regulates crypto-asset service providers under 2024-2025 Securities Law amendments. Self-custody is permitted; exchanges apply KYC/AML under the 2000 Prohibition on Money Laundering Law. [61][59] as of 2026-06-01 Shin Bet is Israel's domestic security service, established 1949. It operates under Basic Law: Human Dignity and Liberty plus classified directives, with FISA-702-class intercept review. [255][202] as of 2026-06-01 NSO Group's Pegasus faced repeated 2024-2025 export-license actions. NSO has been on the US Entity List since November 2021; EU members opened export-control investigations in 2024-2025. [232][133] as of 2026-06-01
United Arab Emirates AE TDRA controls telecom licensing; VoIP services including WhatsApp calls, FaceTime, and Skype are blocked at the carrier layer without a government license. [195][161] as of 2026-06-01 The UAE has no democratically elected institutions; activists who criticize the state are detained, and biometric identification is required for residents via the Emirates ID. [179][275] as of 2026-06-01 Tor is a free overlay network for enabling anonymous communication; the Open Observatory of Network Interference lists the UAE among jurisdictions with Tor bridge interference. [267][271] as of 2026-06-01 VARA licenses virtual asset service providers in the Dubai special development zone, requiring full Travel Rule compliance for transfers above AED 3,500. [113][214] as of 2026-06-01 EFF documents UAE State Security Agency statutory authority under Federal Law No. 1 of 1974 and amendments to detain and surveil without independent court review. [153][110] as of 2026-06-01 In 2024 the UAE Cybercrime Court convicted multiple foreign nationals and ordered device seizure for social media posts critical of public officials. [179][275] as of 2026-06-01
Saudi Arabia SA Saudi Arabia maintains one of the world's most restrictive censorship regimes, with state monitoring of internet and public expression; VoIP and many messaging services are intermittently blocked. [194][153] as of 2026-06-01 Absher is the Saudi government portal that allows men to restrict the travel of female relatives; it integrates the national identity card number and biometric data for all residents. [117][273] as of 2026-06-01 Saudi Arabia has no published statute criminalizing Tor per se; the Anti-Cyber Crime Law (2007) covers tools for unauthorized access, with carrier-level blocking of anonymizers reported since 2019. [253][267] as of 2026-06-01 SAMA regulates Saudi financial institutions; in 2024 it finalized the virtual asset framework extending AML/CFT obligations to crypto-asset service providers and mandating Travel Rule compliance. [99][98] as of 2026-06-01 The Saudi Presidency of State Security holds statutory surveillance authority under the 2017 counter-terrorism law; oversight is internal, with no independent judicial review for intercept orders. [178][194] as of 2026-06-01 Access Now tracked at least six prosecutions in 2024 under the Anti-Cyber Crime Law for social media posts, with prison sentences of up to five years for content deemed to disrupt public order. [273][178] as of 2026-06-01
South Africa ZA POPIA governs data protection and privacy in South Africa; it does not require encryption backdoors or key escrow, and permits use of encryption for lawful data handling. [94][153] as of 2026-06-01 South Africa's Smart ID card, issued by the Department of Home Affairs since 2013, is the primary national identity document; no statute requires ID for general internet access. [256][274] as of 2026-06-01 RICA regulates lawful interception but does not criminalize Tor or VPN use per se; ISPs retain subscriber metadata for prescribed periods and support intercept orders on judicial authorization. [96][274] as of 2026-06-01 The FSCA regulates financial institutions and supervises crypto-asset service providers; in 2022 it declared crypto a financial product under FAIS, requiring licensing. [43][104] as of 2026-06-01 The NCC is a South African intelligence agency responsible for bulk electronic surveillance of foreign communications; a 2019 High Court case ruled its bulk surveillance unconstitutional. [223][257] as of 2026-06-01 Access Now tracked two Cybercrimes Act prosecutions in 2024, both concluded with suspended sentences; the 2020 statute requires judicial authorization for search-and-seizure of devices. [274][94] as of 2026-06-01
Nigeria NG Nigeria has no statute requiring encryption backdoors; the Cybercrimes Act of 2015 requires service providers to retain data and assist lawful intercept, but does not require key escrow. [193][272] as of 2026-06-01 The National Identification Number (NIN) issued by NIMC is required for SIM card activation, bank account opening, and passport applications; no statute requires NIN for general internet access. [227][283] as of 2026-06-01 In June 2021 the Nigerian government suspended Twitter operations; the ban was lifted in January 2022 after the company agreed to local incorporation and lawful-intercept compliance; VPN use spiked. [193][77] as of 2026-06-01 The SEC regulates capital markets and oversees virtual asset service providers; in 2022-2024 it classified crypto as securities and required platforms to register, mandating AML/CFT compliance. [101][143] as of 2026-06-01 The NCC coordinates lawful intercept under the Cybercrimes Act 2015 and the Communications Act 2003; the ONSA holds foreign-intelligence authority with the DSS holding domestic intelligence. [77][283] as of 2026-06-01 Access Now logged multiple 2024 Cybercrimes Act enforcement actions with sentences of two to seven years for online fraud and hate speech; civil society raised due-process concerns. [272][193] as of 2026-06-01
Kenya KE ODPC administers the Data Protection Act, 2019 (in force July 2022) and the Data Protection (Amendment) Act, 2024. It does not require E2EE backdoors. [79][205] as of 2026-06-01 Huduma Namba / NIIMS aimed to be the single digital ID for government services. The 2023 High Court ruling paused mandatory registration pending DPA compliance. [205][64] as of 2026-06-01 Tor usage is legal in Kenya. The CA has not blocked Tor relays. In 2024, during Finance Bill protests, Tor and VPN traffic spiked amid partial shutdowns. [266][206] as of 2026-06-01 CMA regulates Virtual Asset Service Providers under the Capital Markets (Amendment) Act, 2023 and CMA Guidance Note, March 2024. Self-custody is permitted. [13][131] as of 2026-06-01 The National Intelligence Service (NIS) is Kenya's primary domestic intelligence agency, reconstituted under the NIS Act, 2012. It reports to the President. [224][64] as of 2026-06-01 In June-July 2024 Gen Z-led protests against the Finance Bill, 2023 triggered partial communications shutdowns and arrests; the High Court ruled 2024-07-05 on military deployment. [206][204] as of 2026-06-01
Switzerland CH Switzerland revised the FADP in 2023 (in force Sep 1 2023) and the revised act is recognized as adequate by the EU. The act does not impose a backdoor mandate; encryption is treated as an appropriate technical measure. [165][262] as of 2026-06-01 BAKOM regulates Swiss telecoms and broadcasting. There is no mandatory national-ID-for-web regime; the 2021 e-ID Act was rejected in a referendum and parliament shelved the replacement. [168][254] as of 2026-06-01 Tor usage is legal in Switzerland and Tor relays in Switzerland are common. No ISP-level blocking and no known prosecutions of personal Tor users have been documented as of 2025. [266][157] as of 2026-06-01 FINMA regulates Swiss banks, securities firms, and fintech/crypto service providers under FMIA and the Banking Act. KYC/AML applies; self-custody wallets are not banned. [261][49] as of 2026-06-01 The Nachrichtendienst des Bundes (NDB) operates under the Nachrichtendienstgesetz (NDG, Intelligence Service Act) enacted 2015 and operative 2017. NDB has wiretapping authority subject to oversight. [167][40] as of 2026-06-01 The 2020 disclosure that the CIA and BND operated the Crypto AG cipher-device company (1951-2018) supplied manipulated encryption devices to 120+ countries including Switzerland. The historical precedent frames Swiss cryptographic policy. [237][214] as of 2026-06-01
Norway NO Norway has no statute mandating a backdoor in encrypted services. The Norwegian Police Service has publicly opposed the EU Chat Control proposal, citing the impact on law-abiding encryption users. [162][231] as of 2026-06-01 BankID is a widely-deployed electronic identification scheme operated by Norwegian banks. Use is voluntary for most services but effectively required for government and banking; ID-porten (MinID) is the state-side alternative. [10][230] as of 2026-06-01 Tor usage is legal in Norway. Norway has hosted Tor relays since the 2000s; no ISP-level blocking and no known prosecutions of personal Tor users. [266][157] as of 2026-06-01 Finanstilsynet regulates Norwegian financial services, including cryptoasset service providers under the 2018 AML regulations and the EU MiCA-aligned regime now in force. [170][121] as of 2026-06-01 E-tjenesten (the Norwegian foreign intelligence service) operates under the Intelligence Service Act. The service is civilian-controlled and reports to the Ministry of Defence; bulk interception is permitted subject to oversight. [229][243] as of 2026-06-01 Datatilsynet enforces the Norwegian Personal Data Act (Personopplysningsloven) which implements the GDPR. 2024-2025 enforcement actions include cookie-consent rulings and AI-training-data investigations. [228][139] as of 2026-06-01
Turkey TR BTK regulates Turkish telecoms and has authority to block content under Law 5651. Turkey has not enacted a backdoor mandate, but BTK pressure has produced de facto E2E weakening on messaging [186][268] as of 2026-06-01 TCKN is the universal national ID number, issued by NVI and required for SIM activation, e-Devlet, e-Imza. SIM-card registration ties the TCKN to mobile broadband access. [269][198] as of 2026-06-01 BTK has periodically blocked Tor entry nodes and major VPN providers. As of 2024-2025 Tor usage requires bridges or obfuscation; personal use is not prosecuted, but the underlying access is blocked [196][267] as of 2026-06-01 Turkey's BDDK banned banks from dealing in crypto in April 2021. Self-custody is not illegal but the banking ban and 2024 SPK regulations push users to licensed exchanges. AML is enforced via MASAK. [126][210] as of 2026-06-01 MIT has the broadest FISA-702-class authority in Turkey, formalized by Law 2937 (2014) and expanded by Law 6710 (2016) and 2018 state-of-emergency decrees. Limited judicial oversight. [270][221] as of 2026-06-01 Turkey is identified as a Pegasus customer; in 2024 Citizen Lab documented ongoing Pegasus use against journalists, opposition figures, and civil society. Ankara has not acknowledged or denied. [239][134] as of 2026-06-01

Per-country breakdown (mobile-friendly)

The table above is wide. The same data, presented as cards on narrow screens, lives below. Each card shows all six cells for one country.

EU-level (Chat Control) EU
  1. 1. End-to-end encryption legal status

    The Regulation to Prevent and Combat Child Sexual Abuse (Child Sexual Abuse Regulation, or CSAR), commonly known as Chat Control, is a European Union regulation proposed on 11 May 2022. Civil society

    Sources: [136], [136] As of 2026-06-01

  2. 2. Digital ID / web access regime

    eIDAS Regulation 910/2014 governs electronic identification and trust services in the EU; the 2024 amendment (Reg (EU) 2024/1183) adds a European Digital Identity Wallet with selective disclosure.

    Sources: [158], [158] As of 2026-06-01

  3. 3. Anonymity network legality

    EDRi: anonymity tools such as Tor and I2P are legal at EU level. The proposed CSAR (Chat Control) does not itself ban Tor but EDRi warns it would be used to attack E2EE.

    Sources: [278], [279] As of 2026-06-01

  4. 4. Crypto regulation

    MiCA creates a single EU rulebook for issuers of asset-referenced tokens, e-money tokens, and crypto-asset service providers. It entered into force 29 June 2023, full effect 30 December 2024.

    Sources: [213], [36] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Europol is the EU law-enforcement agency; its legal basis is Regulation (EU) 2016/794. Europol supports EU member states in fighting serious and organised crime, including cyber-crime.

    Sources: [163], [163], [254] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Europol's IOCTA 2024 reports a continued rise in cybercrime across the EU and the persistent use of encrypted communications by organised crime groups; Europol supports COSI.

    Sources: [38], [37] As of 2026-06-01

Germany DE
  1. 1. End-to-end encryption legal status

    German upper-level federal agency founded in 1991, in charge of computer and communication security. Expertise includes cryptography, counter eavesdropping, and certification of security products.

    Sources: [41], [174] As of 2026-06-01

  2. 2. Digital ID / web access regime

    NetzDG (Gesetz zur Verbesserung der Rechtsdurchsetzung in sozialen Netzwerken, Network Enforcement Act) is a German social-media regulation law that requires social platforms with more than two millio

    Sources: [226], [112] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is a free overlay network for enabling anonymous communication. It is built on free and open-source software run by over seven thousand volunteer-operated relays worldwide.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    BaFin is Germany's integrated financial regulator and the national competent authority under MiCA for crypto-asset service providers in Germany. It enforces the Kreditwesengesetz on crypto custody.

    Sources: [9], [208] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Federal Intelligence Service (Bundesnachrichtendienst, BND) is the foreign intelligence agency of Germany, formed 1 April 1956. The BND operates under the BND-Gesetz and is subject to oversight by

    Sources: [166], [11] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    BSI is Germany's federal cybersecurity agency. The BSI Act 2009 was updated in 2023 to broaden BSI's powers over critical infrastructure operators and enable proactive vulnerability scanning.

    Sources: [41], [277] As of 2026-06-01

France FR
  1. 1. End-to-end encryption legal status

    France's CNIL enforces GDPR and the 1978 Data Protection Act; it treats encryption as a recommended security measure and there is no French statute mandating backdoors in E2EE products.

    Sources: [138], [5] As of 2026-06-01

  2. 2. Digital ID / web access regime

    FranceConnect is the French state single sign-on identity broker, launched in 2016, that lets citizens log in to over 1,400 public services using a verified national identity provider.

    Sources: [173], [259] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is free and open-source software for anonymous communication. Its use is legal in France; there are no known prosecutions of individuals solely for running or using Tor.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    MiCA is the EU regulation on crypto-assets, in force from 2023, providing a harmonised licensing regime for crypto-asset service providers across the EU including France.

    Sources: [213], [3] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Loi renseignement 2015 autorise les services francais a utiliser des techniques de surveillance algorithmique en temps reel sous controle de la CNCTR pour la securite nationale.

    Sources: [211], [150] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The 2024 Paris Olympics deployed algorithmic video surveillance (experimented under loi n 2023-380) for crowd monitoring in public spaces; the experiment was scheduled to lapse in March 2025.

    Sources: [115], [19] As of 2026-06-01

United Kingdom GB
  1. 1. End-to-end encryption legal status

    An Act to make provision for and in connection with the regulation by Ofcom of certain internet services; for and in connection with communications offences; and for connected purposes. Citation 2023

    Sources: [83], [235], [263] As of 2026-06-01

  2. 2. Digital ID / web access regime

    An Act to make provision for the regulation of the processing of information relating to individuals; to make provision in connection with the GDPR; and for connected purposes.

    Sources: [28], [148] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in the United Kingdom; ISPs are not required to block Tor relays. The UK Home Office has funded Tor indirectly through the Open Technology Fund for anti-censorship.

    Sources: [267], [282] As of 2026-06-01

  4. 4. Crypto regulation

    The Financial Services and Markets Act 2000, as amended in 2023, brought crypto-asset activities into the UK regulatory perimeter; the FCA is the AML supervisor for cryptoasset firms.

    Sources: [44], [70] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Investigatory Powers Act 2016 is an Act of the Parliament of the United Kingdom that makes provision about the interception of communications, equipment interference, the acquisition and retention

    Sources: [199], [97], [177] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The ICO is the UK data protection regulator. In 2024-2025 it continued enforcement against Clearview AI and ordered deletion of UK residents' biometric data.

    Sources: [54], [58] As of 2026-06-01

Italy IT
  1. 1. End-to-end encryption legal status

    Italy's Garante per la protezione dei dati personali is the independent data-protection authority enforcing the Italian Personal Data Protection Code. Operates under Codice della Privacy, D.Lgs..

    Sources: [62], [174] As of 2026-06-01

  2. 2. Digital ID / web access regime

    SPID (Sistema Pubblico di Identita Digitale) is the public digital identity system that allows citizens and businesses to access all online services of the Italian Public Administration with a.

    Sources: [106], [160] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is free and open-source software for enabling anonymous communication. Legal to use in Italy; no ISP-level blocking. Italian case law (Cass. pen. 27146/2016) affirmed that mere use of Tor is not.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    MiCA (Regulation (EU) 2023/1114) is the EU framework regulating crypto-asset issuers, service providers, and trading platforms. Italy applies MiCA through the Ministry of Economy and Finance and.

    Sources: [213], [121] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Italian intelligence is coordinated by the Department of Information for Security (DIS). External intelligence is AISE, internal security is AISI, and cyber is ACN, the National Cybersecurity.

    Sources: [63], [245] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    On 20 December 2024 the Garante concluded its ChatGPT probe with a 15M EUR fine against OpenAI for unlawfully processing personal data to train GPT models. The EU's first major AI-specific GDPR.

    Sources: [174], [277] As of 2026-06-01

Spain ES
  1. 1. End-to-end encryption legal status

    The Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos, AEPD) is the independent supervisory authority for data protection in Spain, established by the LOPDGDD (2018).

    Sources: [105], [174] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Cl@ve is the Spanish national electronic identification system operated by the Tax Agency (AEAT), providing both persistent (Cl@ve Permanente) and one-time (Cl@ve Ocasional) credentials for citizens.

    Sources: [18], [258] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal to use in Spain; no ISP-level blocking. The AEPD has not initiated enforcement against Tor users. Criminal procedure (LO 13/2015) requires judicial authorization for traffic.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    MiCA (Regulation (EU) 2023/1114) is the EU framework regulating crypto-asset issuers, service providers, and trading platforms. Spain applies it through the CNMV and Banco de Espana, with the Law.

    Sources: [213], [102] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Centro Nacional de Inteligencia (CNI) is Spain's official intelligence agency, succeeded the CESID in 2002. It reports to the Second Vice-President of the Government and operates under the Ley.

    Sources: [17], [244] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The AEPD publishes monthly enforcement dashboards; in 2024 it issued 9,890 sanctions, 0.12% of the EU's total GDPR fines, and 4,860 informal data-protection audits under the LOPDGDD framework.

    Sources: [105], [258] As of 2026-06-01

Netherlands NL
  1. 1. End-to-end encryption legal status

    The Autoriteit Persoonsgegevens (AP) is the Dutch Data Protection Authority, established under the AVG (GDPR Implementation Act, Uitvoeringswet AVG) and successor to the CBP since 2016. The.

    Sources: [8], [174] As of 2026-06-01

  2. 2. Digital ID / web access regime

    DigiD is an identity management platform operated by Logius (Ministry of the Interior and Kingdom Relations) that allows Dutch residents to authenticate themselves when accessing Dutch government.

    Sources: [32], [158] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal to use in the Netherlands; no ISP-level blocking. The Dutch DPA has supported the right to anonymity. The 2016 referendum rejected broad dragnet-retention powers under the previous.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    MiCA (Regulation (EU) 2023/1114) is the EU framework regulating crypto-asset issuers, service providers, and trading platforms. The Netherlands implements via De Nederlandsche Bank and the AFM.

    Sources: [213], [31] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The AIVD (Algemene Inlichtingen- en Veiligheidsdienst) is the Dutch domestic intelligence service. Its legal basis is the Wiv 2017 (Intelligence and Security Services Act 2017), which replaced the.

    Sources: [51], [67] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    AP issued 30.5M EUR fine on Uber (2024), 290M EUR on Meta (2023), 525K EUR on Haga Lyceum (2019). In 2024-2025 AP opened probes on TikTok, Clearview AI, and on the SyRI (system risk indication).

    Sources: [8], [277] As of 2026-06-01

Sweden SE
  1. 1. End-to-end encryption legal status

    The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) is Sweden's data protection authority since 1 January 2021, succeeding the Datainspektionen. Sweden has not adopted a.

    Sources: [55], [174] As of 2026-06-01

  2. 2. Digital ID / web access regime

    BankID is a national electronic identification system in Sweden, issued by banks (Finansiell ID-Teknik BID AB, owned by Danske Bank, Handelsbanken, ICA Banken, Lansforsakringar Bank, Nordea, SEB.

    Sources: [10], [158] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in Sweden; no ISP-level blocking. The FRA (National Defence Radio Establishment) is authorised to collect internet cable traffic crossing Swedish borders under the Signalspaning Act.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    Finansinspektionen is the Swedish financial supervisory authority. Under MiCA, FI is the competent authority for CASPs in Sweden. In 2024 it issued 23 supervised CASP registrations under the Wft.

    Sources: [47], [46] As of 2026-06-01

  5. 5. Government surveillance authority scope

    FRA (Foersvarets radioanstalt) is Sweden's signals intelligence agency. Since 2009 (SFS 2008:717, signalspaning), FRA has been authorised to intercept cross-border cable traffic under judicial.

    Sources: [72], [107] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    IMY issued the Swedish DPA's first GDPR fine in 2020 against a school (200K SEK) for using facial recognition. In 2023 it fined the Stockholm health authority 35M SEK for unlawful use of Clearview.

    Sources: [55], [277] As of 2026-06-01

Poland PL
  1. 1. End-to-end encryption legal status

    UODO is the Polish data protection authority. Poland has not adopted any E2EE backdoor mandate; GDPR applies fully as an EU member state.

    Sources: [87], [175] As of 2026-06-01

  2. 2. Digital ID / web access regime

    mObywatel is the official Polish government mobile application for displaying identity documents (mDowod) and accessing e-government services. It is opt-in, not a precondition for general web access.

    Sources: [69], [34] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is a free overlay network for enabling anonymous communication. It is legal in Poland; no public orders require ISPs to block Tor relays.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    KNF is Poland's integrated financial regulator. It supervises crypto-asset service providers under MiCA and enforces AML obligations, including the travel rule.

    Sources: [91], [213] As of 2026-06-01

  5. 5. Government surveillance authority scope

    ABW is the Polish domestic intelligence and counter-intelligence agency, established in 2002. Powers include surveillance, telecommunications interception, and access to communications metadata.

    Sources: [57], [14], [218] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    UODO has issued GDPR fines and orders against major platforms 2024-2025, on biometric data and consent for advertising. The 2024-2025 caseload is published on the UODO site.

    Sources: [87], [277] As of 2026-06-01

Ireland IE
  1. 1. End-to-end encryption legal status

    The DPC is Ireland's data protection authority. Ireland has not adopted any E2EE backdoor mandate; GDPR applies fully. The DPC handles many EU one-stop-shop cases.

    Sources: [29], [175] As of 2026-06-01

  2. 2. Digital ID / web access regime

    MyGovID is Ireland's online identity service for accessing government services. It is not a precondition for general web access; private sites are not required to use it.

    Sources: [71], [222] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is a free overlay network for enabling anonymous communication. It is legal in Ireland; no public orders require ISPs to block Tor relays.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    The Central Bank of Ireland supervises crypto-asset service providers under MiCA as the national competent authority. Self-custody wallets are not prohibited; CASP services require authorisation.

    Sources: [16], [213] As of 2026-06-01

  5. 5. Government surveillance authority scope

    An Garda Siochana is the national police service of Ireland. The Garda National Cyber Crime Bureau handles cybercrime and electronic evidence under the CJA 2006.

    Sources: [50], [149] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The DPC issued multiple GDPR decisions 2024-2026, including rulings on major US tech firms' EU operations, data-transfer mechanisms, and AI training data. Decisions are public on the DPC website.

    Sources: [29], [277] As of 2026-06-01

United States US
  1. 1. End-to-end encryption legal status

    The EARN IT Act (Eliminating Abusive and Rampant Neglect of Interactive Technologies Act) is a proposed United States law announced in the 118th United States Congress, with Section 230 of the Communi

    Sources: [151], [161], [159] As of 2026-06-01

  2. 2. Digital ID / web access regime

    The REAL ID Act of 2005 sets federal standards for state-issued ID. As of 7 May 2025, REAL ID is enforced for domestic air travel, but there is no national ID requirement to access the open web.

    Sources: [248], [207] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in the United States; no US law requires ISPs to block Tor relays. The US State Department and the National Science Foundation have funded Tor development since the early 2000s.

    Sources: [267], [154] As of 2026-06-01

  4. 4. Crypto regulation

    The Bank Secrecy Act of 1970 (BSA) requires US financial institutions, including crypto money services businesses registered with FinCEN, to keep records and file reports on currency transactions.

    Sources: [125], [48] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Foreign Intelligence Surveillance Act of 1978 is a United States federal law authorizing electronic surveillance of foreign intelligence information. Section 702 of the FISA Amendments Act of 2008

    Sources: [172], [164], [155] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The FBI is the US domestic intelligence and security service. It has used FISA Section 702 and NSL authorities; in 2024-2025 it issued multiple Section 702 reauthorisation reports to Congress.

    Sources: [39], [152] As of 2026-06-01

Canada CA
  1. 1. End-to-end encryption legal status

    PIPEDA is the Canadian federal privacy law for private-sector organisations; it does not prohibit end-to-end encryption and treats strong encryption as a recommended safeguard for personal data.

    Sources: [242], [81] As of 2026-06-01

  2. 2. Digital ID / web access regime

    The Online Harms Act (Bill C-63) was tabled in the House of Commons on 20 February 2024. It would create a Digital Safety Commission and impose duties on social media services.

    Sources: [234], [82] As of 2026-06-01

  3. 3. Anonymity network legality

    Section 2(b) of the Charter protects freedom of expression. The Supreme Court of Canada has recognised this includes a right to anonymous speech; Tor use is not in itself illegal.

    Sources: [129], [267] As of 2026-06-01

  4. 4. Crypto regulation

    FINTRAC is Canada's financial intelligence unit. Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, crypto-asset service providers are reporting entities subject to KYC.

    Sources: [45], [84] As of 2026-06-01

  5. 5. Government surveillance authority scope

    CSE is Canada's foreign signals intelligence agency under National Defence, with a domestic cyber-defence mandate. Foreign intelligence is authorised under the CSE Act.

    Sources: [140], [130] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Public Safety Canada describes the Critical Cyber Systems Protection Act (part of Bill C-26, Royal Assent 18 December 2024) as regulating cyber security in finance, telecoms, energy, and transport.

    Sources: [4], [252] As of 2026-06-01

Mexico MX
  1. 1. End-to-end encryption legal status

    INAI (formerly IFAI) is Mexico's national institute for transparency, access to information, and personal data protection. Mexico has not adopted any E2EE backdoor mandate.

    Sources: [182], [188] As of 2026-06-01

  2. 2. Digital ID / web access regime

    CURP is the unique population registry code assigned to every resident of Mexico. Required for government procedures, tax filing, and bank account opening, not general web access.

    Sources: [145], [103] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is a free overlay network for anonymous communication. It is legal in Mexico; no public orders require ISPs to block Tor relays, though the government uses surveillance tools.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    CNBV is the Mexican financial regulator. The 2018 Ley Fintech regulates fintech institutions including crypto-asset platforms; exchanges require authorisation. Self-custody wallets are not prohibited.

    Sources: [20], [171] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The CNI is Mexico's civilian intelligence agency, created in 2018 to replace CISEN. It coordinates intelligence, including signals intelligence and counter-narcotics operations.

    Sources: [17], [100] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    INAI has issued significant LFPDPPP enforcement decisions 2024-2025 against banks, fintechs, and retailers for personal data handling. The 2024 Pegasus scandal triggered INAI actions.

    Sources: [182], [217] As of 2026-06-01

Australia AU
  1. 1. End-to-end encryption legal status

    Gives the Australian Federal Police, ASIO, and the Australian Signals Directorate three new powers: Technical Assistance Requests (TARs), Technical Assistance Notices (TANs), and Technical Capabili...

    Sources: [111], [215], [215] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Establishes a voluntary Digital ID system overseen by the Digital ID Regulator within the Treasury. Australian Government, state/territory agencies, and accredited private sector participants can u...

    Sources: [33], [233] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in Australia; no law requires ISPs to block Tor relays. The Australian eSafety Commissioner has not pursued any blocking order against Tor entry nodes.

    Sources: [267], [78] As of 2026-06-01

  4. 4. Crypto regulation

    AUSTRAC is Australia's financial intelligence unit. Under the AML/CTF Act 2006, digital currency exchange providers must register with AUSTRAC and apply KYC, with reporting obligations on transfers.

    Sources: [6], [208] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Establishes ASIO. Section 25 authorises ASIO to obtain a warrant to intercept telecommunications, search premises, and (under the 2024 amendments) conduct 'tracking device' warrants.

    Sources: [7], [109], [122] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The eSafety Commissioner is Australia's online safety regulator. Under the Online Safety Act 2021, the Commissioner issues takedown notices and Basic Online Safety Expectations to platforms.

    Sources: [35], [108] As of 2026-06-01

New Zealand NZ
  1. 1. End-to-end encryption legal status

    The Privacy Act 2020 is New Zealand's principal data-protection law. New Zealand has not adopted any E2EE backdoor mandate; the Act requires reasonable security safeguards.

    Sources: [93], [246] As of 2026-06-01

  2. 2. Digital ID / web access regime

    RealMe is a New Zealand government-issued online identity, operated by the Department of Internal Affairs. Used for government services; not a precondition for general web access.

    Sources: [249], [95] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is a free overlay network for enabling anonymous communication. It is legal in New Zealand; no public orders require ISPs to block Tor relays.

    Sources: [267], [278] As of 2026-06-01

  4. 4. Crypto regulation

    The FMA is the New Zealand financial regulator. The FMCA 2013 and 2022 Taxation Act impose AML/CFT obligations on crypto-asset service providers. Self-custody is not prohibited.

    Sources: [42], [121] As of 2026-06-01

  5. 5. Government surveillance authority scope

    GCSB is the New Zealand signals-intelligence and information-assurance agency. Powers include foreign-intelligence collection and cybersecurity under the ISA 2017.

    Sources: [52], [76] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The Privacy Commissioner has issued enforcement decisions 2024-2026 against agencies for breaches of the Privacy Act 2020, including data breach notifications.

    Sources: [80], [277] As of 2026-06-01

India IN
  1. 1. End-to-end encryption legal status

    IT Act 2000 (No. 21/2000) s 69 grants government interception powers. India has not mandated a backdoor, but 2021 IT Rules Rule 4(2) requires traceability of first originator on covered messengers.

    Sources: [187], [203] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Aadhaar is India's biometric national ID issued by UIDAI. KYC and SIM activation require it. Statutory basis is the Aadhaar Act 2016; Supreme Court narrowed use in Puttaswamy (2017).

    Sources: [116], [203] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is not banned in India. ISPs are not under a blanket blocking order, but specific Tor exit nodes have been intermittently blocked during Kashmir internet shutdowns.

    Sources: [267], [191] As of 2026-06-01

  4. 4. Crypto regulation

    RBI Circular April 6, 2018 (DBR.No.BP.BC.104) banned banks from crypto dealings; Supreme Court struck it down in IMAI v RBI (2020). Crypto is legal but taxed 30% under Finance Act 2022.

    Sources: [251], [142] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Indian Telegraph Act 1885 s 5(2) allows interception on sovereignty, security, or public-order grounds. IT Act 2000 s 69 extends similar powers to computer data. No FISA-702 analog.

    Sources: [183], [135] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    India was identified as a Pegasus operator in 2021 WhatsApp-snooping revelations. In 2023-2024 the Supreme Court-appointed technical committee continued to investigate use against journalists and

    Sources: [239], [216] As of 2026-06-01

Japan JP
  1. 1. End-to-end encryption legal status

    Japan's telecommunications framework is governed by the Telecommunications Business Act (1984, last amended 2023) and the Act on the Limitation of Liability of Providers (2001).

    Sources: [264], [144], [220] As of 2026-06-01

  2. 2. Digital ID / web access regime

    APPI is Japan's main data-protection law, most recently amended in 2022. It does not require a national ID for general web use; the My Number system is for government services and tax purposes only.

    Sources: [118], [88] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in Japan; ISPs are not required to block Tor relays. The Tor Project has documented cooperation with Japanese academic researchers for traffic-analysis research.

    Sources: [267], [68] As of 2026-06-01

  4. 4. Crypto regulation

    The FSA supervises banks, insurers, and cryptoasset service providers. The 2024 amendment to the Payment Services Act reformed cryptoasset taxation (carried-forward losses) and the FSA's enforcemen...

    Sources: [169], [142] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Japan's Act on Interception of Communications (1999, 2016 amendment) authorizes telecommunications interception for investigations of organized crime and serious offenses. Requires judicial warrant.

    Sources: [209], [247] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The NPA is Japan's central coordinating police body. In 2024-2025 it reported a continuing increase in cyber-crime cases including phishing and investment fraud.

    Sources: [74], [92] As of 2026-06-01

South Korea KR
  1. 1. End-to-end encryption legal status

    Regulates information and communications service providers. Article 64 authorizes the Korea Internet and Security Agency (KISA) to request data preservation.

    Sources: [53], [209] As of 2026-06-01

  2. 2. Digital ID / web access regime

    South Korea's PIPA, in force since 2011, requires explicit consent for personal information. Real-name verification for online services was held unconstitutional in 2012 by the Constitutional Court.

    Sources: [240], [90] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in South Korea; there are no public blocking orders against Tor relays. Use of Tor for legitimate anonymity is not in itself a criminal offence under Korean law.

    Sources: [267], [75] As of 2026-06-01

  4. 4. Crypto regulation

    Financial Action Task Force (FATF) travel rule: virtual asset service providers must transmit originator and beneficiary information for cryptoasset transfers.

    Sources: [1], [142] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The NIS is South Korea's primary intelligence agency, established 1999. Under the National Intelligence Service Act it conducts foreign and domestic intelligence and counter-espionage.

    Sources: [225], [65] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Korea Internet and Security Agency (KISA) English-language home. KISA published the 2024 Internet Security Annual Report documenting 1,247 data-breach notifications in 2024, with 73% originating fr...

    Sources: [66], [241] As of 2026-06-01

Singapore SG
  1. 1. End-to-end encryption legal status

    Singapore's Cybersecurity Act 2018 regulates critical information infrastructure operators. It does not impose E2EE backdoors; CII operators must report incidents, not weaken encryption.

    Sources: [147], [86] As of 2026-06-01

  2. 2. Digital ID / web access regime

    The PDPA 2012 does not require a national ID for general web access. Singapore's Singpass digital ID is used for government and selected private services, not as a precondition for the open internet.

    Sources: [86], [25] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in Singapore; no public orders require ISPs to block Tor relays. Anonymity tools for legitimate purposes are not in themselves prohibited; content offences are enforced as in any case.

    Sources: [267], [189] As of 2026-06-01

  4. 4. Crypto regulation

    Regulates digital payment token services under the Monetary Authority of Singapore (MAS). Major Payment Institution (MPI) licence required for DPT services above SGD 5 million monthly turnover.

    Sources: [85], [142] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Allows detention without trial for up to two years (renewable) for persons acting in a manner prejudicial to the security of Singapore.

    Sources: [56], [23] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The Cyber Security Agency of Singapore administers the Cybersecurity Act 2018. In 2024-2025 CSA invoked Section 19 incident reporting powers against CII operators after ransomware incidents.

    Sources: [26], [23] As of 2026-06-01

China CN
  1. 1. End-to-end encryption legal status

    The state regulates cryptography. Cryptography is divided into core, ordinary, and commercial categories. State secrets and personal information are protected by core/ordinary categories with.

    Sources: [24], [280], [284] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Personal information handlers must obtain consent for collection/use. Real-name identity verification is mandated for internet services. Cross-border transfer requires government security assessment.

    Sources: [89], [280], [180] As of 2026-06-01

  3. 3. Anonymity network legality

    Authorities restricted access to anticensorship tools, blocking access to unauthorized VPNs and penalizing people who used them (see B1 and C3).

    Sources: [280], [180], [287] As of 2026-06-01

  4. 4. Crypto regulation

    Data is classified by national security importance. Cross-border data flow is restricted. Cryptocurrency transactions are not recognized as legal tender; the PBOC and 10 ministries banned crypto.

    Sources: [30], [280], [180] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Network operators must store data on servers in China and provide technical support to national security and law enforcement agencies. Real-name verification is required for users.

    Sources: [27], [280], [284] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Independent filmmaker Chen Pinlin was detained in November 2023 after posting online a documentary with footage of the historic White Paper protests. He faces up to five years in prison. Sun Lin.

    Sources: [280], [180], [287] As of 2026-06-01

Russia RU
  1. 1. End-to-end encryption legal status

    The government continued to block critical news sites and developed increasingly sophisticated technical and legislative measures to block virtual private networks (VPNs). Government agencies.

    Sources: [281], [181], [287] As of 2026-06-01

  2. 2. Digital ID / web access regime

    New laws imposed extensive limitations on rights and access to state services for perceived draft evaders. SIM-card registration is mandatory, tied to government-issued identification via the.

    Sources: [281], [181], [285] As of 2026-06-01

  3. 3. Anonymity network legality

    In March 2024, a law that bans websites from posting information about circumvention tools, including VPNs, or advertising for VPNs came into effect; shortly after, the regulator blocked 30 webpages.

    Sources: [281], [181], [286] As of 2026-06-01

  4. 4. Crypto regulation

    Russia adopted a digital-ruble framework in 2023 and legalized cryptocurrency mining in 2024 under Federal Law No. 221-FZ, with heavy reporting requirements and central-bank oversight of.

    Sources: [281], [181], [285] As of 2026-06-01

  5. 5. Government surveillance authority scope

    This system (SORM) involves storing user traffic and must be approved by the Federal Security Service (FSB). For the first violation, a fine of 0.001 to 0.003 percent of annual revenue is.

    Sources: [281], [181], [287] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    In November 2023, the Supreme Court named the international LGBT movement as an extremist organization, which has facilitated website blocks, content removal, and criminal cases. In March 2024, a.

    Sources: [281], [181], [287] As of 2026-06-01

Indonesia ID
  1. 1. End-to-end encryption legal status

    Indonesia's UU ITE (Law 11/2008, amended by Law 19/2016 and Law 1/2024) governs electronic information and transactions. The law does not mandate an E2E backdoor;

    Sources: [192], [146] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Kartu Tanda Penduduk (KTP) is the universal national ID, with e-KTP issued under Law 23/2006 on Population Administration. Required for SIM activation, banking, government services.

    Sources: [184], [219] As of 2026-06-01

  3. 3. Anonymity network legality

    Indonesia blocks millions of URLs through the Trust Positif / Nawala system. Tor is not explicitly banned, but Komdigi has ordered ISP blocking of Tor directory authorities;

    Sources: [192], [267] As of 2026-06-01

  4. 4. Crypto regulation

    OJK Regulation 27/POJK.03/2024 (replacing Bappebti Reg 8/2021) regulates crypto asset trading. Trading is legal on licensed exchanges; self-custody is allowed; FATF travel rule applies.

    Sources: [238], [124] As of 2026-06-01

  5. 5. Government surveillance authority scope

    BIN has the broadest FISA-702-class authority in Indonesia under Law 17/2011 on State Intelligence. The 2020 amendments let BIN conduct cyber operations and access telecom metadata;

    Sources: [260], [185] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    In 2023 Citizen Lab and Amnesty documented Predator and Pegasus use against Indonesian civil society and journalists; in 2024 Komnas HAM opened a formal inquiry into commercial spyware targeting

    Sources: [239], [192] As of 2026-06-01

Brazil BR
  1. 1. End-to-end encryption legal status

    Marco Civil (Law 12.965/2014) protects net neutrality, privacy, and freedom of expression. Article 10 affirms inviolability of communications except by court order.

    Sources: [212], [176] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Cadastro de Pessoas Fisicas (CPF) is the universal tax ID used for KYC. The 2023 digital CNH and e-Titulo extend identification online. No law requires a national ID to access the open web.

    Sources: [127], [212] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is legal in Brazil and not blocked at the ISP level. Brazilian users are a major share of the global Tor relay pool. No known prosecutions for personal Tor use exist.

    Sources: [267], [250] As of 2026-06-01

  4. 4. Crypto regulation

    Lei 14.478/2022 created a virtual-asset service provider (VASP) regime overseen by Banco Central. Self-custody is legal; exchanges must register, comply with AML/CFT, and report transactions.

    Sources: [123], [210] As of 2026-06-01

  5. 5. Government surveillance authority scope

    ABIN, under the GSI, is Brazil's primary foreign and counter-intelligence agency. The 2023-2024 PF operation revealed alleged illegal surveillance on Supreme Court justices, prosecutors, and

    Sources: [128], [236] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    On 8 January 2023 supporters of ex-president Bolsonaro stormed Praca dos Tres Poderes in Brasilia. Investigations used cellphone tower dumps and facial recognition to identify thousands.

    Sources: [114], [250] As of 2026-06-01

Argentina AR
  1. 1. End-to-end encryption legal status

    Argentina's DNPDP administers Personal Data Protection Act 25.326 (2000). Argentina has held an EU Adequacy Decision since 2003; the regime does not impose E2EE backdoors.

    Sources: [73], [2] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Argentina does not impose a mandatory national digital ID for general web access. The Mi Argentina app (CUIL/CUIT-based) authenticates users for government services.

    Sources: [2], [12] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor usage is legal in Argentina. No ISP-level blocking reported. Argentine prosecutors have not brought cases targeting Tor use per se; wiretaps require court order.

    Sources: [266], [190] As of 2026-06-01

  4. 4. Crypto regulation

    BCRA Communication A 7506 (2022) requires virtual asset service providers to register and apply KYC/AML. Self-custody is permitted; exchanges report under FATF travel rule.

    Sources: [15], [21] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The AFI replaced the former SIDE in 2015 under Ley 27.126, updated by Decreto 50/2019. It conducts foreign and domestic intelligence under judicial oversight.

    Sources: [120], [12] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Argentina was among countries identified in 2023-2025 Pegasus disclosures; in 2024 a federal judge ordered records on provincial spyware purchases.

    Sources: [239], [119] As of 2026-06-01

Chile CL
  1. 1. End-to-end encryption legal status

    Chile has no law mandating encryption backdoors or key escrow; commercial encryption products are freely available and used in banking and government services without statutory weakening.

    Sources: [197], [276] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Chile's national identity card (cedula de identidad) is issued by the Civil Registry and required for voting and most government services; no statute requires ID for general internet access.

    Sources: [137], [132] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor and commercial VPN use is legal in Chile; ISPs do not block anonymizer services. Derechos Digitales documented no prosecutions for anonymized communication use through 2024.

    Sources: [276], [141] As of 2026-06-01

  4. 4. Crypto regulation

    The CMF regulates banks, securities, and insurance; in 2023 it extended prudential reporting obligations to virtual asset service providers, mandating Travel Rule compliance for crypto transfers.

    Sources: [22], [137] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Agencia Nacional de Inteligencia conducts foreign intelligence; domestic intelligence is split between PDI and Carabineros with court-ordered intercept authorization required since 2000.

    Sources: [132], [276] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Derechos Digitales logged two cybercrime convictions in 2024 under Ley No. 19.223, with sentencing limited to fines and short probationary terms for non-state offenses.

    Sources: [276], [197] As of 2026-06-01

Israel IL
  1. 1. End-to-end encryption legal status

    Privacy Protection Law, 1981 regulates processing of personal data. It does not mandate E2EE backdoors; lawful intercept operates under security service warrants.

    Sources: [201], [200] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Teudat Zehut is required for in-person government services. Israel does not require it for routine web access. A 2024 facial-biometric push was paused by the Supreme Court.

    Sources: [265], [60] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor usage is legal in Israel and not blocked at ISP level. No public cases targeting users solely for running Tor. Unit 8200 runs relays but does not restrict civilian use.

    Sources: [266], [156] As of 2026-06-01

  4. 4. Crypto regulation

    ISA regulates crypto-asset service providers under 2024-2025 Securities Law amendments. Self-custody is permitted; exchanges apply KYC/AML under the 2000 Prohibition on Money Laundering Law.

    Sources: [61], [59] As of 2026-06-01

  5. 5. Government surveillance authority scope

    Shin Bet is Israel's domestic security service, established 1949. It operates under Basic Law: Human Dignity and Liberty plus classified directives, with FISA-702-class intercept review.

    Sources: [255], [202] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    NSO Group's Pegasus faced repeated 2024-2025 export-license actions. NSO has been on the US Entity List since November 2021; EU members opened export-control investigations in 2024-2025.

    Sources: [232], [133] As of 2026-06-01

United Arab Emirates AE
  1. 1. End-to-end encryption legal status

    TDRA controls telecom licensing; VoIP services including WhatsApp calls, FaceTime, and Skype are blocked at the carrier layer without a government license.

    Sources: [195], [161] As of 2026-06-01

  2. 2. Digital ID / web access regime

    The UAE has no democratically elected institutions; activists who criticize the state are detained, and biometric identification is required for residents via the Emirates ID.

    Sources: [179], [275] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor is a free overlay network for enabling anonymous communication; the Open Observatory of Network Interference lists the UAE among jurisdictions with Tor bridge interference.

    Sources: [267], [271] As of 2026-06-01

  4. 4. Crypto regulation

    VARA licenses virtual asset service providers in the Dubai special development zone, requiring full Travel Rule compliance for transfers above AED 3,500.

    Sources: [113], [214] As of 2026-06-01

  5. 5. Government surveillance authority scope

    EFF documents UAE State Security Agency statutory authority under Federal Law No. 1 of 1974 and amendments to detain and surveil without independent court review.

    Sources: [153], [110] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    In 2024 the UAE Cybercrime Court convicted multiple foreign nationals and ordered device seizure for social media posts critical of public officials.

    Sources: [179], [275] As of 2026-06-01

Saudi Arabia SA
  1. 1. End-to-end encryption legal status

    Saudi Arabia maintains one of the world's most restrictive censorship regimes, with state monitoring of internet and public expression; VoIP and many messaging services are intermittently blocked.

    Sources: [194], [153] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Absher is the Saudi government portal that allows men to restrict the travel of female relatives; it integrates the national identity card number and biometric data for all residents.

    Sources: [117], [273] As of 2026-06-01

  3. 3. Anonymity network legality

    Saudi Arabia has no published statute criminalizing Tor per se; the Anti-Cyber Crime Law (2007) covers tools for unauthorized access, with carrier-level blocking of anonymizers reported since 2019.

    Sources: [253], [267] As of 2026-06-01

  4. 4. Crypto regulation

    SAMA regulates Saudi financial institutions; in 2024 it finalized the virtual asset framework extending AML/CFT obligations to crypto-asset service providers and mandating Travel Rule compliance.

    Sources: [99], [98] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Saudi Presidency of State Security holds statutory surveillance authority under the 2017 counter-terrorism law; oversight is internal, with no independent judicial review for intercept orders.

    Sources: [178], [194] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Access Now tracked at least six prosecutions in 2024 under the Anti-Cyber Crime Law for social media posts, with prison sentences of up to five years for content deemed to disrupt public order.

    Sources: [273], [178] As of 2026-06-01

South Africa ZA
  1. 1. End-to-end encryption legal status

    POPIA governs data protection and privacy in South Africa; it does not require encryption backdoors or key escrow, and permits use of encryption for lawful data handling.

    Sources: [94], [153] As of 2026-06-01

  2. 2. Digital ID / web access regime

    South Africa's Smart ID card, issued by the Department of Home Affairs since 2013, is the primary national identity document; no statute requires ID for general internet access.

    Sources: [256], [274] As of 2026-06-01

  3. 3. Anonymity network legality

    RICA regulates lawful interception but does not criminalize Tor or VPN use per se; ISPs retain subscriber metadata for prescribed periods and support intercept orders on judicial authorization.

    Sources: [96], [274] As of 2026-06-01

  4. 4. Crypto regulation

    The FSCA regulates financial institutions and supervises crypto-asset service providers; in 2022 it declared crypto a financial product under FAIS, requiring licensing.

    Sources: [43], [104] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The NCC is a South African intelligence agency responsible for bulk electronic surveillance of foreign communications; a 2019 High Court case ruled its bulk surveillance unconstitutional.

    Sources: [223], [257] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Access Now tracked two Cybercrimes Act prosecutions in 2024, both concluded with suspended sentences; the 2020 statute requires judicial authorization for search-and-seizure of devices.

    Sources: [274], [94] As of 2026-06-01

Nigeria NG
  1. 1. End-to-end encryption legal status

    Nigeria has no statute requiring encryption backdoors; the Cybercrimes Act of 2015 requires service providers to retain data and assist lawful intercept, but does not require key escrow.

    Sources: [193], [272] As of 2026-06-01

  2. 2. Digital ID / web access regime

    The National Identification Number (NIN) issued by NIMC is required for SIM card activation, bank account opening, and passport applications; no statute requires NIN for general internet access.

    Sources: [227], [283] As of 2026-06-01

  3. 3. Anonymity network legality

    In June 2021 the Nigerian government suspended Twitter operations; the ban was lifted in January 2022 after the company agreed to local incorporation and lawful-intercept compliance; VPN use spiked.

    Sources: [193], [77] As of 2026-06-01

  4. 4. Crypto regulation

    The SEC regulates capital markets and oversees virtual asset service providers; in 2022-2024 it classified crypto as securities and required platforms to register, mandating AML/CFT compliance.

    Sources: [101], [143] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The NCC coordinates lawful intercept under the Cybercrimes Act 2015 and the Communications Act 2003; the ONSA holds foreign-intelligence authority with the DSS holding domestic intelligence.

    Sources: [77], [283] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Access Now logged multiple 2024 Cybercrimes Act enforcement actions with sentences of two to seven years for online fraud and hate speech; civil society raised due-process concerns.

    Sources: [272], [193] As of 2026-06-01

Kenya KE
  1. 1. End-to-end encryption legal status

    ODPC administers the Data Protection Act, 2019 (in force July 2022) and the Data Protection (Amendment) Act, 2024. It does not require E2EE backdoors.

    Sources: [79], [205] As of 2026-06-01

  2. 2. Digital ID / web access regime

    Huduma Namba / NIIMS aimed to be the single digital ID for government services. The 2023 High Court ruling paused mandatory registration pending DPA compliance.

    Sources: [205], [64] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor usage is legal in Kenya. The CA has not blocked Tor relays. In 2024, during Finance Bill protests, Tor and VPN traffic spiked amid partial shutdowns.

    Sources: [266], [206] As of 2026-06-01

  4. 4. Crypto regulation

    CMA regulates Virtual Asset Service Providers under the Capital Markets (Amendment) Act, 2023 and CMA Guidance Note, March 2024. Self-custody is permitted.

    Sources: [13], [131] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The National Intelligence Service (NIS) is Kenya's primary domestic intelligence agency, reconstituted under the NIS Act, 2012. It reports to the President.

    Sources: [224], [64] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    In June-July 2024 Gen Z-led protests against the Finance Bill, 2023 triggered partial communications shutdowns and arrests; the High Court ruled 2024-07-05 on military deployment.

    Sources: [206], [204] As of 2026-06-01

Switzerland CH
  1. 1. End-to-end encryption legal status

    Switzerland revised the FADP in 2023 (in force Sep 1 2023) and the revised act is recognized as adequate by the EU. The act does not impose a backdoor mandate; encryption is treated as an appropriate technical measure.

    Sources: [165], [262] As of 2026-06-01

  2. 2. Digital ID / web access regime

    BAKOM regulates Swiss telecoms and broadcasting. There is no mandatory national-ID-for-web regime; the 2021 e-ID Act was rejected in a referendum and parliament shelved the replacement.

    Sources: [168], [254] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor usage is legal in Switzerland and Tor relays in Switzerland are common. No ISP-level blocking and no known prosecutions of personal Tor users have been documented as of 2025.

    Sources: [266], [157] As of 2026-06-01

  4. 4. Crypto regulation

    FINMA regulates Swiss banks, securities firms, and fintech/crypto service providers under FMIA and the Banking Act. KYC/AML applies; self-custody wallets are not banned.

    Sources: [261], [49] As of 2026-06-01

  5. 5. Government surveillance authority scope

    The Nachrichtendienst des Bundes (NDB) operates under the Nachrichtendienstgesetz (NDG, Intelligence Service Act) enacted 2015 and operative 2017. NDB has wiretapping authority subject to oversight.

    Sources: [167], [40] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    The 2020 disclosure that the CIA and BND operated the Crypto AG cipher-device company (1951-2018) supplied manipulated encryption devices to 120+ countries including Switzerland. The historical precedent frames Swiss cryptographic policy.

    Sources: [237], [214] As of 2026-06-01

Norway NO
  1. 1. End-to-end encryption legal status

    Norway has no statute mandating a backdoor in encrypted services. The Norwegian Police Service has publicly opposed the EU Chat Control proposal, citing the impact on law-abiding encryption users.

    Sources: [162], [231] As of 2026-06-01

  2. 2. Digital ID / web access regime

    BankID is a widely-deployed electronic identification scheme operated by Norwegian banks. Use is voluntary for most services but effectively required for government and banking; ID-porten (MinID) is the state-side alternative.

    Sources: [10], [230] As of 2026-06-01

  3. 3. Anonymity network legality

    Tor usage is legal in Norway. Norway has hosted Tor relays since the 2000s; no ISP-level blocking and no known prosecutions of personal Tor users.

    Sources: [266], [157] As of 2026-06-01

  4. 4. Crypto regulation

    Finanstilsynet regulates Norwegian financial services, including cryptoasset service providers under the 2018 AML regulations and the EU MiCA-aligned regime now in force.

    Sources: [170], [121] As of 2026-06-01

  5. 5. Government surveillance authority scope

    E-tjenesten (the Norwegian foreign intelligence service) operates under the Intelligence Service Act. The service is civilian-controlled and reports to the Ministry of Defence; bulk interception is permitted subject to oversight.

    Sources: [229], [243] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Datatilsynet enforces the Norwegian Personal Data Act (Personopplysningsloven) which implements the GDPR. 2024-2025 enforcement actions include cookie-consent rulings and AI-training-data investigations.

    Sources: [228], [139] As of 2026-06-01

Turkey TR
  1. 1. End-to-end encryption legal status

    BTK regulates Turkish telecoms and has authority to block content under Law 5651. Turkey has not enacted a backdoor mandate, but BTK pressure has produced de facto E2E weakening on messaging

    Sources: [186], [268] As of 2026-06-01

  2. 2. Digital ID / web access regime

    TCKN is the universal national ID number, issued by NVI and required for SIM activation, e-Devlet, e-Imza. SIM-card registration ties the TCKN to mobile broadband access.

    Sources: [269], [198] As of 2026-06-01

  3. 3. Anonymity network legality

    BTK has periodically blocked Tor entry nodes and major VPN providers. As of 2024-2025 Tor usage requires bridges or obfuscation; personal use is not prosecuted, but the underlying access is blocked

    Sources: [196], [267] As of 2026-06-01

  4. 4. Crypto regulation

    Turkey's BDDK banned banks from dealing in crypto in April 2021. Self-custody is not illegal but the banking ban and 2024 SPK regulations push users to licensed exchanges. AML is enforced via MASAK.

    Sources: [126], [210] As of 2026-06-01

  5. 5. Government surveillance authority scope

    MIT has the broadest FISA-702-class authority in Turkey, formalized by Law 2937 (2014) and expanded by Law 6710 (2016) and 2018 state-of-emergency decrees. Limited judicial oversight.

    Sources: [270], [221] As of 2026-06-01

  6. 6. Notable enforcement actions 2024-2026

    Turkey is identified as a Pegasus customer; in 2024 Citizen Lab documented ongoing Pegasus use against journalists, opposition figures, and civil society. Ankara has not acknowledged or denied.

    Sources: [239], [134] As of 2026-06-01

Methodology

This table is the substrate for the country deep-dive series (linked at the bottom). The 29 country targets come from the project brief; we added the EU as a 30th row for the Chat Control vote, and a small handful of high-impact non-EU jurisdictions (Switzerland, Norway, Turkey) to round out the geographic coverage. That puts the working count at 34.

Six questions, defined

  1. End-to-end encryption legal status. free of backdoors / mandated backdoor / required escrow / no law
  2. Digital ID / web access regime. mandatory national ID for web / for local software / age-verification laws / site licensing or blocking / none
  3. Anonymity network legality. Tor/I2P usage legal, ISP-level blocking, known prosecutions
  4. Crypto regulation. self-custody, exchange KYC/AML, travel rule
  5. Government surveillance authority scope. FISA-702-class, EO 12333-class, EU national security, no law
  6. Notable enforcement actions 2024-2026. timestamped, cited

Source tiers (priority order)

  1. Tier 1. Regulator text / court ruling / statute (e.g. FCC, BNetzA, Ofcom, primary statute text)
  2. Tier 2. Tier-1 NGO (EFF, Privacy International, Article 19, Access Now, WITNESS) or tertiary reference (Wikipedia) anchored to primary sources
  3. Tier 3. UN body / tier-2 NGO (UN OHCHR, CDT, EPIC, Open Rights Group, Digitale Gesellschaft, EDRi, Derechos Digitales)
  4. Tier 4. Law firm / academic analysis (Stanford CIS, Lawfare, Just Security, Hogan Lovells, Linklaters)

Per-cell "as of" date

Surveillance law changes fast. Each cell shows the date we last verified the cited sources, rounded to the first of the month for readability. The newest source in the cell wins. If a cell has not been touched in 2026, it reflects the Archivist's last sweep cycle (see Sources).

What this table is not

This is a current-state snapshot, not a legal opinion. For a specific situation (you are relocating, your company is deploying encryption in a new market, you are facing a regulator), hire a lawyer licensed in the relevant jurisdiction. The sources are starting points, not substitutes for advice.

Sources

Sources are deduped by URL across all 34 country rows. A source cited in five cells still gets one footnote number. The list is sorted by source tier (primary first), then alphabetically by title.

  1. [1] Tier 1 Specific Financial Information Act, Act No. 18522 of 2021, last amended 2024. Act on the Reporting and Use of Specific Financial Transaction Information (Travel Rule, 2022 amendment) (accessed 2026-06-15)
  2. [2] Tier 1 Agencia de Acceso a la Informacion Publica (Argentina gov) (accessed 2026-06-17)
  3. [3] Tier 1 AMF (Autorite des Marches Financiers) (accessed 2026-06-16)
  4. [4] Tier 1 An Act respecting cyber security (Bill C-26) (accessed 2026-06-16)
  5. [5] Tier 1 Loi n 2004-801 du 6 aout 2004. ANSSI regulations and guidance (accessed 2026-06-16)
  6. [6] Tier 1 Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). AUSTRAC (Australian Transaction Reports and Analysis Centre) (accessed 2026-06-16)
  7. [7] Tier 1 ASIO Act 1979 (Cth), last amended 2024. Australian Security Intelligence Organisation Act 1979 (accessed 2026-06-15)
  8. [8] Tier 1 Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). Autoriteit Persoonsgegevens (AP) - English site (accessed 2026-06-17)
  9. [9] Tier 1 BaFin (Federal Financial Supervisory Authority) (accessed 2026-06-16)
  10. [10] Tier 1 Lag (2000:243) om straff for vissa penninghanteringsbrott (AML context). BankID (Wikipedia) (accessed 2026-06-17)
  11. [11] Tier 1 BfDI home page (Federal Commissioner for Data Protection) (accessed 2026-06-15)
  12. [12] Tier 1 Ley 25.326, art. 5 and art. 28. Boletin Oficial de la Republica Argentina (primary) (accessed 2026-06-17)
  13. [13] Tier 1 Capital Markets (Amendment) Act, 2023. Capital Markets Authority of Kenya (Kenya gov) (accessed 2026-06-17)
  14. [14] Tier 1 Central Anti-Corruption Bureau (CBA, Poland) (accessed 2026-06-17)
  15. [15] Tier 1 BCRA Communication A 7506/2022. Central Bank of Argentina (BCRA) (Wikipedia) (accessed 2026-06-17)
  16. [16] Tier 1 Markets in Crypto-Assets Regulation (EU) 2023/1114. Central Bank of Ireland (accessed 2026-06-17)
  17. [17] Tier 1 Ley 11/2002 (CNI statute); Estrategia de Seguridad Nacional 2021. Centro Nacional de Inteligencia (CNI) - Wikipedia (accessed 2026-06-17)
  18. [18] Tier 1 Real Decreto 203/2021 (electronic identification regulations). Cl@ve - electronic identification system (official) (accessed 2026-06-17)
  19. [19] Tier 1 CNIL news listing (SREN coverage) (accessed 2026-06-16)
  20. [20] Tier 1 Ley para Regular las Instituciones de Tecnologia Financiera (Fintech Law, 2018). Comision Nacional Bancaria y de Valores (CNBV, Mexico) (accessed 2026-06-17)
  21. [21] Tier 1 CNV RG 1015/2024; AFIP RG 4619/2024. Comision Nacional de Valores (CNV) (Argentina gov) (accessed 2026-06-17)
  22. [22] Tier 1 Ley Fintec, Ley No. 21.521 of 2023. Comision para el Mercado Financiero (accessed 2026-06-17)
  23. [23] Tier 1 Criminal Procedure Code 2010, Subdivisions (4) and (5). Criminal Procedure Code (Cap. 68) - Subdivisions (4) and (5) (accessed 2026-06-15)
  24. [24] Tier 1 Cryptography Law of the People's Republic of China, effective Jan 1, 2020. Cryptography Law of the People's Republic of China (translation) (accessed 2026-06-17)
  25. [25] Tier 1 Cyber Security Agency of Singapore (accessed 2026-06-16)
  26. [26] Tier 1 Cybersecurity Act enforcement (accessed 2026-06-16)
  27. [27] Tier 1 Cybersecurity Law of the PRC, effective June 1, 2017; National Intelligence Law 2017. Cybersecurity Law of the People's Republic of China (translation) (accessed 2026-06-17)
  28. [28] Tier 1 Data Protection Act 2018, c. 12. Data Protection Act 2018 (legislation.gov.uk) (accessed 2026-06-15)
  29. [29] Tier 1 Data Protection Act 2018 (No. 7 of 2018). Data Protection Commission (Ireland) (accessed 2026-06-17)
  30. [30] Tier 1 Data Security Law of the PRC, effective Sept 1, 2021; PBOC et al. joint notice on virtual currency, Sept 24, 2021. Data Security Law of the People's Republic of China (translation) (accessed 2026-06-17)
  31. [31] Tier 1 Wet ter voorkoming van witwassen en financieren van terrorisme (Wwft). De Nederlandsche Bank - Wikipedia (accessed 2026-06-17)
  32. [32] Tier 1 Wet digitale overheid (2022); General Administrative Law Act (Awb). DigiD (Wikipedia) (accessed 2026-06-17)
  33. [33] Tier 1 Digital ID Act 2024 (Cth). Digital ID Act 2024 (Cth) (accessed 2026-06-15)
  34. [34] Tier 1 e-Dowod - Polish national eID (accessed 2026-06-17)
  35. [35] Tier 1 Online Safety Act 2021 (Cth). eSafety Commissioner (accessed 2026-06-16)
  36. [36] Tier 1 Regulation (EU) 2023/1113. European Commission: Digital Finance (accessed 2026-06-16)
  37. [37] Tier 1 European Data Protection Board (EDPB) (accessed 2026-06-16)
  38. [38] Tier 1 Europol cybercrime (accessed 2026-06-16)
  39. [39] Tier 1 Federal Bureau of Investigation (FBI) (accessed 2026-06-16)
  40. [40] Tier 1 FDPIC Act (DSG), SR 235.3. Federal Data Protection and Information Commissioner FDPIC (edoeb.admin.ch) (accessed 2026-06-17)
  41. [41] Tier 1 BSI Act (BSIG), BGBl. I 2009 S. 2821. Federal Office for Information Security / BSI (Wikipedia) (accessed 2026-06-15)
  42. [42] Tier 1 Financial Markets Conduct Act 2013; Anti-Money Laundering and Countering Financing of Terrorism Act 2009. Financial Markets Authority (FMA, NZ) (accessed 2026-06-17)
  43. [43] Tier 1 FSCA Declaration of Crypto Assets as Financial Product, 2022. Financial Sector Conduct Authority (accessed 2026-06-17)
  44. [44] Tier 1 Financial Services and Markets Act 2000, c. 8; Financial Services and Markets Act 2023, c. 29. Financial Services and Markets Act 2000 (accessed 2026-06-16)
  45. [45] Tier 1 Proceeds of Crime (Money Laundering) and Terrorist Financing Act, S.C. 2000, c. 17. Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) (accessed 2026-06-16)
  46. [46] Tier 1 Reg. (EU) 2023/1113 (TFR - Transfer of Funds Regulation, travel rule). Finansinspektionen - Wikipedia (accessed 2026-06-17)
  47. [47] Tier 1 Lag (2017:1147) om aatgaerder mot penningtvaett och finansiering av terrorism (mutual evaluation 2024). Finansinspektionen (FI) - official site (accessed 2026-06-17)
  48. [48] Tier 1 FinCEN (Financial Crimes Enforcement Network) (accessed 2026-06-16)
  49. [49] Tier 1 FINMA Fintech License (2019) and AMLO (2017/2019). FINMA - Official site (finma.ch) (accessed 2026-06-17)
  50. [50] Tier 1 Garda Siochana Act 2005; Communications (Retention of Data) Act 2011; CJC Act 2006. Garda Siochana (Ireland) (accessed 2026-06-17)
  51. [51] Tier 1 Wet op de inlichtingen- en veiligheidsdiensten 2017 (Wiv 2017); Evaluatiewet Wiv 2022. General Intelligence and Security Service (AIVD) - Wikipedia (accessed 2026-06-17)
  52. [52] Tier 1 Government Communications Security Bureau Act 2003; Intelligence and Security Act 2017. Government Communications Security Bureau (GCSB, NZ) (accessed 2026-06-17)
  53. [53] Tier 1 Information and Communications Network Act, Act No. 5054, last amended 2024. Information and Communications Network Act (ICNA, Act No. 5054 of 1995) (accessed 2026-06-15)
  54. [54] Tier 1 Information Commissioner's Office (ICO) (accessed 2026-06-16)
  55. [55] Tier 1 Lag (2018:218) med kompletterande bestaemmelser till EU:s dataskyddsforordning. Integritetsskyddsmyndigheten (IMY) - official site (accessed 2026-06-17)
  56. [56] Tier 1 Internal Security Act 1960 (Cap. 143), as amended 2022. Internal Security Act 1960 (Cap. 143) (accessed 2026-06-15)
  57. [57] Tier 1 Act on the Internal Security Agency and the Intelligence Services Agency of 24 May 2002. Internal Security Agency (ABW, Poland) (accessed 2026-06-17)
  58. [58] Tier 1 Investigatory Powers Act 2016, c. 25. Investigatory Powers Act 2016 (full text) (accessed 2026-06-16)
  59. [59] Tier 1 Israel Anti-Money Laundering Authority (Wikipedia) (accessed 2026-06-17)
  60. [60] Tier 1 Israel Privacy Protection Authority (gov.il) (accessed 2026-06-17)
  61. [61] Tier 1 Securities Law, 5728-1968 (as amended 2024). Israel Securities Authority (ISA) (Wikipedia) (accessed 2026-06-17)
  62. [62] Tier 1 D.Lgs. 30 giugno 2003, n. 196 (Codice della Privacy). Italian Data Protection Authority (Garante) - official site (accessed 2026-06-17)
  63. [63] Tier 1 L. 3 agosto 2007, n. 124; L. 7 agosto 2012, n. 133. Italian Intelligence Services (Wikipedia) (accessed 2026-06-17)
  64. [64] Tier 1 Kenya Information and Communications Act, 1998. Kenya Communications Authority (CA) primary (accessed 2026-06-17)
  65. [65] Tier 1 KISA (Korea Internet and Security Agency) (accessed 2026-06-16)
  66. [66] Tier 1 KISA: Annual Internet Security Report 2024 (English landing) (accessed 2026-06-15)
  67. [67] Tier 1 Wiv 2017; Wiv 2002 (predecessor). Military Intelligence and Security Service (MIVD) - Wikipedia (accessed 2026-06-17)
  68. [68] Tier 1 Ministry of Internal Affairs and Communications (Japan) (accessed 2026-06-16)
  69. [69] Tier 1 mObywatel - Polish government digital ID app (accessed 2026-06-17)
  70. [70] Tier 1 MLR 2017, SI 2017/692; UK Funds Transfer Regulation 2017. Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (accessed 2026-06-16)
  71. [71] Tier 1 MyGovID (Ireland) (accessed 2026-06-17)
  72. [72] Tier 1 Lag (2008:717) om signalspaning i forsvarsunderrattelseverksamhet; Lag (2022:1318) signalspaningslag. National Defence Radio Establishment (FRA) - Wikipedia (accessed 2026-06-17)
  73. [73] Tier 1 Ley 25.326, Boletin Oficial 30/11/2000. National Directorate for Personal Data Protection (Wikipedia) (accessed 2026-06-17)
  74. [74] Tier 1 National Police Agency (Japan) (accessed 2026-06-16)
  75. [75] Tier 1 National Police Agency (South Korea) (accessed 2026-06-16)
  76. [76] Tier 1 New Zealand Security Intelligence Service (NZSIS) (accessed 2026-06-17)
  77. [77] Tier 1 Nigerian Communications Commission (accessed 2026-06-17)
  78. [78] Tier 1 Office of the Australian Information Commissioner (OAIC) (accessed 2026-06-16)
  79. [79] Tier 1 Data Protection Act, 2019; DPA 2024 amendment. Office of the Data Protection Commissioner (Kenya gov) (accessed 2026-06-17)
  80. [80] Tier 1 Office of the Privacy Commissioner (NZ) - enforcement (accessed 2026-06-17)
  81. [81] Tier 1 Office of the Privacy Commissioner of Canada (accessed 2026-06-16)
  82. [82] Tier 1 Office of the Privacy Commissioner of Canada (accessed 2026-06-16)
  83. [83] Tier 1 Online Safety Act 2023, c. 50. Online Safety Act 2023 (legislation.gov.uk) (accessed 2026-06-15)
  84. [84] Tier 1 Ontario Securities Commission (OSC) (accessed 2026-06-16)
  85. [85] Tier 1 Payment Services Act 2019, last amended 2024. Payment Services Act 2019 (Act 2 of 2019) (accessed 2026-06-15)
  86. [86] Tier 1 Personal Data Protection Act 2012 (Singapore) (accessed 2026-06-16)
  87. [87] Tier 1 Personal Data Protection Act of 10 May 2018 (Journal of Laws 2019 item 1781). Personal Data Protection Office (UODO) - official site (accessed 2026-06-17)
  88. [88] Tier 1 Personal Information Protection Commission (PPC) Japan (accessed 2026-06-16)
  89. [89] Tier 1 Personal Information Protection Law of the PRC, effective Nov 1, 2021. Personal Information Protection Law of the People's Republic of China (translation) (accessed 2026-06-17)
  90. [90] Tier 1 PIPC (Personal Information Protection Commission) (accessed 2026-06-16)
  91. [91] Tier 1 Act on Anti-Money Laundering and Counter-Terrorist Financing of 1 March 2018. Polish Financial Supervision Authority (KNF) (accessed 2026-06-17)
  92. [92] Tier 1 PPC Japan legal page (accessed 2026-06-16)
  93. [93] Tier 1 Privacy Act 2020 (No. 31). Privacy Commissioner (Office of the Privacy Commissioner, NZ) (accessed 2026-06-17)
  94. [94] Tier 1 Protection of Personal Information Act 4 of 2013. Protection of Personal Information Act, 2013 (accessed 2026-06-17)
  95. [95] Tier 1 RealMe (NZ government) (accessed 2026-06-17)
  96. [96] Tier 1 RICA, Act 70 of 2002. Regulation of Interception of Communications and Provision of Communication-Related Information Act (accessed 2026-06-17)
  97. [97] Tier 1 Regulation of Investigatory Powers Act 2000, c. 23. Regulation of Investigatory Powers Act 2000 (legislation.gov.uk) (accessed 2026-06-15)
  98. [98] Tier 1 Saudi Arabian Monetary Authority (accessed 2026-06-17)
  99. [99] Tier 1 SAMA Virtual Asset Regulation Framework, 2024. Saudi Central Bank (accessed 2026-06-17)
  100. [100] Tier 1 Secretariat of National Defense (Mexico) (accessed 2026-06-17)
  101. [101] Tier 1 SEC Nigeria Rules on Virtual Asset Service Providers, 2022. Securities and Exchange Commission (Nigeria) (accessed 2026-06-17)
  102. [102] Tier 1 Real Decreto-Ley 7/2021 (transposing EU 5AMLD). SEPBLAC (Executive Service of the Commission for the Prevention of Money Laundering) (accessed 2026-06-17)
  103. [103] Tier 1 Servicio de Administracion Tributaria (SAT) - Mexico (accessed 2026-06-17)
  104. [104] Tier 1 South African Reserve Bank (accessed 2026-06-17)
  105. [105] Tier 1 Ley Organica 3/2018 (LOPDGDD). Spanish Data Protection Agency (AEPD) - official site (accessed 2026-06-17)
  106. [106] Tier 1 DPCM 24 ottobre 2014 (SPID technical rules); D.L. 76/2020 art. 64 (mandatory PA adoption). SPID - Public Digital Identity System (official) (accessed 2026-06-17)
  107. [107] Tier 1 Polislag (1984:387); Saekerhetsskyddslag (2018:585). Swedish Security Service (Saekerhetspolisen) - Wikipedia (accessed 2026-06-17)
  108. [108] Tier 1 Telecommunications (Interception and Access) Act 1979 (Cth). Telecommunications (Interception and Access) Act 1979 (accessed 2026-06-16)
  109. [109] Tier 1 Telecommunications (Interception and Access) Act 1979 (Cth). Telecommunications (Interception and Access) Act 1979 (TIA Act) (accessed 2026-06-15)
  110. [110] Tier 1 Telecommunications and Digital Government Regulatory Authority (accessed 2026-06-17)
  111. [111] Tier 1 Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth). Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (accessed 2026-06-15)
  112. [112] Tier 1 TTDSG, BGBl. I 2021 S. 1979, 2044. TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz) (accessed 2026-06-15)
  113. [113] Tier 1 Dubai Law No. 4 of 2022; Cabinet Decision No. 111 of 2022. Virtual Asset Regulatory Authority (VARA) (accessed 2026-06-17)
  114. [114] Tier 2 2023 Brazilian Congress attack (Wikipedia) (accessed 2026-06-17)
  115. [115] Tier 2 Loi n 2023-380 du 19 mai 2023. 2024 Summer Olympics surveillance law (accessed 2026-06-16)
  116. [116] Tier 2 Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. Aadhaar (Wikipedia) (accessed 2026-06-17)
  117. [117] Tier 2 Absher (accessed 2026-06-17)
  118. [118] Tier 2 Act on the Protection of Personal Information, Act No. 57 of 2003 (as amended). Act on the Protection of Personal Information (APPI) (accessed 2026-06-16)
  119. [119] Tier 2 ADC (Asociacion por los Derechos Civiles) Argentina (accessed 2026-06-17)
  120. [120] Tier 2 Ley 27.126, 2015; Decreto 50/2019. Agencia Federal de Inteligencia (Wikipedia) (accessed 2026-06-17)
  121. [121] Tier 2 D.Lgs. 21 novembre 2007, n. 231; D.Lgs. 90/2017 (EU 4AMLD transposition). Anti-money laundering (AML) - Wikipedia (accessed 2026-06-17)
  122. [122] Tier 2 Australian Signals Directorate (Wikipedia) (accessed 2026-06-15)
  123. [123] Tier 2 Lei No. 14.478, 21 December 2022 (Marco Legal Cripto). Banco Central do Brasil (Wikipedia) (accessed 2026-06-17)
  124. [124] Tier 2 PADG No. 22/15/PADG/2020. Bank Indonesia (Wikipedia) (accessed 2026-06-17)
  125. [125] Tier 2 Bank Secrecy Act, 31 U.S.C. ss 5311-5336. Bank Secrecy Act (accessed 2026-06-16)
  126. [126] Tier 2 BDDK Decision No. 2021/1; SPK Regulation on Crypto Asset Service Providers (2024). Banking Regulation and Supervision Agency (Wikipedia) (accessed 2026-06-17)
  127. [127] Tier 2 Cadastro de Pessoas Fisicas (CPF), Receita Federal. Brazilian identity card (Wikipedia) (accessed 2026-06-17)
  128. [128] Tier 2 Lei No. 9.883, 7 December 1999 (criacao da ABIN). Brazilian Intelligence Agency (Wikipedia) (accessed 2026-06-17)
  129. [129] Tier 2 Canadian Charter of Rights and Freedoms, Part I of the Constitution Act, 1982. Canadian Charter of Rights and Freedoms (accessed 2026-06-16)
  130. [130] Tier 2 Canadian Security Intelligence Service Act, R.S.C. 1985, c. C-23. Canadian Security Intelligence Service (CSIS) (accessed 2026-06-16)
  131. [131] Tier 2 Capital Markets Authority of Kenya (Wikipedia) (accessed 2026-06-17)
  132. [132] Tier 2 Carabineros de Chile (accessed 2026-06-17)
  133. [133] Tier 2 Cellebrite (Wikipedia) (accessed 2026-06-17)
  134. [134] Tier 2 Censorship in Turkey (Wikipedia) (accessed 2026-06-17)
  135. [135] Tier 2 Central Monitoring System (Wikipedia) (accessed 2026-06-17)
  136. [136] Tier 2 Commission proposal COM/2022/209 final. Chat Control (CSAR) (accessed 2026-06-15)
  137. [137] Tier 2 Chile (accessed 2026-06-17)
  138. [138] Tier 2 CNIL (Commission Nationale Informatique et Libertes) (accessed 2026-06-16)
  139. [139] Tier 2 Cybersecurity Act (Cybersikkerhetsloven), LOV-2024-12-13. Communications in Norway (Wikipedia) (accessed 2026-06-17)
  140. [140] Tier 2 Communications Security Establishment Act, S.C. 2019, c. 13, s. 76. Communications Security Establishment (CSE) (accessed 2026-06-16)
  141. [141] Tier 2 Crime in Chile (accessed 2026-06-17)
  142. [142] Tier 2 Cryptocurrency (Wikipedia) (accessed 2026-06-17)
  143. [143] Tier 2 Cryptocurrency in Nigeria (accessed 2026-06-17)
  144. [144] Tier 2 Cryptography in Japan (Wikipedia) (accessed 2026-06-15)
  145. [145] Tier 2 CURP - Clave Unica de Registro de Poblacion (accessed 2026-06-17)
  146. [146] Tier 2 Cybercrime law (Wikipedia) (accessed 2026-06-17)
  147. [147] Tier 2 Cybersecurity Act 2018 (Act 9 of 2018). Cybersecurity Act (Singapore) (accessed 2026-06-16)
  148. [148] Tier 2 Data Protection Act 2018 (Wikipedia) (accessed 2026-06-15)
  149. [149] Tier 2 Defence Forces (Ireland) (accessed 2026-06-17)
  150. [150] Tier 2 DGSI (Direction Generale de la Securite Interieure) (accessed 2026-06-16)
  151. [151] Tier 2 EARN IT Act (accessed 2026-06-15)
  152. [152] Tier 2 EFF cases (accessed 2026-06-16)
  153. [153] Tier 2 Federal Law No. 1 of 1974 on State Security; amendments 2008, 2012. EFF Free Speech Issues (accessed 2026-06-17)
  154. [154] Tier 2 EFF issue page: Anonymity (accessed 2026-06-16)
  155. [155] Tier 2 EFF Section 702 issue page (accessed 2026-06-15)
  156. [156] Tier 2 EFF Tor Legal FAQ (accessed 2026-06-17)
  157. [157] Tier 2 EFF: Tor and the EFF (eff.org) (accessed 2026-06-17)
  158. [158] Tier 2 Regulation (EU) 910/2014; Regulation (EU) 2024/1183 (eIDAS 2.0). eIDAS - Wikipedia (accessed 2026-06-17)
  159. [159] Tier 2 18 U.S.C. ss 2510-2522 (Wiretap Act), 2701-2712 (Stored Communications Act). Electronic Communications Privacy Act of 1986 (Wikipedia) (accessed 2026-06-15)
  160. [160] Tier 2 L. 6 agosto 2008, n. 133; D.M. 8 novembre 2007. Electronic Identity Card (CIE) - Wikipedia (accessed 2026-06-17)
  161. [161] Tier 2 Encrypting the Web (EFF issue page) (accessed 2026-06-15)
  162. [162] Tier 2 Encryption (Wikipedia) (accessed 2026-06-17)
  163. [163] Tier 2 Regulation (EU) 2016/794. Europol (Wikipedia) (accessed 2026-06-15)
  164. [164] Tier 2 Exec. Order No. 12333, 46 Fed. Reg. 59941 (1981). Executive Order 12333 (accessed 2026-06-15)
  165. [165] Tier 2 Federal Act on Data Protection (FADP), SR 235.1 (revised 2023). Federal Act on Data Protection (FADP, revised 2023) (Wikipedia) (accessed 2026-06-17)
  166. [166] Tier 2 Federal Intelligence Service (BND) (Wikipedia) (accessed 2026-06-15)
  167. [167] Tier 2 Nachrichtendienstgesetz (NDG), SR 121 (2015). Federal Intelligence Service (NDB) (Wikipedia) (accessed 2026-06-17)
  168. [168] Tier 2 Federal Act on Electronic Identification Services (e-ID Act), rejected in referendum 2021. Federal Office of Communications (BAKOM) (Wikipedia) (accessed 2026-06-17)
  169. [169] Tier 2 Payment Services Act, Act No. 59 of 2009. Financial Services Agency (Japan) (Wikipedia) (accessed 2026-06-15)
  170. [170] Tier 2 Anti-money laundering regulations (FOR-2018-09-14); MiCA implementation. Finanstilsynet (Wikipedia) (accessed 2026-06-17)
  171. [171] Tier 2 Fintech - Wikipedia (accessed 2026-06-17)
  172. [172] Tier 2 50 U.S.C. ch. 36 (FISA); 50 U.S.C. s 1881a (Section 702). Foreign Intelligence Surveillance Act of 1978 (accessed 2026-06-15)
  173. [173] Tier 2 FranceConnect (French Wikipedia) (accessed 2026-06-16)
  174. [174] Tier 2 Regulation (EU) 2016/679 (GDPR). GDPR (General Data Protection Regulation) (accessed 2026-06-16)
  175. [175] Tier 2 General Data Protection Regulation (accessed 2026-06-17)
  176. [176] Tier 2 Lei Geral de Proteção de Dados (LGPD), Lei No. 13.709/2018. General Personal Data Protection Law (Wikipedia) (accessed 2026-06-17)
  177. [177] Tier 2 Government Communications Headquarters (GCHQ) (accessed 2026-06-15)
  178. [178] Tier 2 Counter-Terrorism and Financing of Terrorism Law, Royal Decree No. M/21 of 2017. Human rights in Saudi Arabia (accessed 2026-06-17)
  179. [179] Tier 2 Emirates Identity Act, Federal Law No. 9 of 1972 (and successor ICA statutes). Human rights in the United Arab Emirates (accessed 2026-06-17)
  180. [180] Tier 2 Human Rights Watch World Report 2024: China (accessed 2026-06-17)
  181. [181] Tier 2 Human Rights Watch World Report 2024: Russia (accessed 2026-06-17)
  182. [182] Tier 2 Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP, 2010). IFAI (INAI predecessor) - Wikipedia (accessed 2026-06-17)
  183. [183] Tier 2 Indian Telegraph Act 1885 (Act 13/1885), s 5(2). Indian Telegraph Act, 1885 (Wikipedia) (accessed 2026-06-17)
  184. [184] Tier 2 Undang-Undang No. 23 Tahun 2006 tentang Administrasi Kependudukan. Indonesian identity card (Wikipedia) (accessed 2026-06-17)
  185. [185] Tier 2 Indonesian National Police (Wikipedia) (accessed 2026-06-17)
  186. [186] Tier 2 Law No. 5651 (Internet and Broadcasting Regulation, 2007). Information and Communication Technologies Authority (Wikipedia) (accessed 2026-06-17)
  187. [187] Tier 2 Information Technology Act 2000, No. 21 of 2000, s 69. Information Technology Act 2000 (Wikipedia) (accessed 2026-06-17)
  188. [188] Tier 2 Instituto Nacional de Transparencia (INAI) - Spanish Wikipedia (accessed 2026-06-17)
  189. [189] Tier 2 Internal Security Act 1960 (Cap. 143). Internal Security Act (Singapore) (accessed 2026-06-16)
  190. [190] Tier 2 Internet censorship in Argentina (Wikipedia) (accessed 2026-06-17)
  191. [191] Tier 2 Internet censorship in India (Wikipedia) (accessed 2026-06-17)
  192. [192] Tier 2 Undang-Undang No. 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik (UU ITE). Internet censorship in Indonesia (Wikipedia) (accessed 2026-06-17)
  193. [193] Tier 2 Cybercrimes (Prohibition, Prevention, etc.) Act, 2015. Internet censorship in Nigeria (accessed 2026-06-17)
  194. [194] Tier 2 Internet censorship in Saudi Arabia (accessed 2026-06-17)
  195. [195] Tier 2 Internet censorship in the United Arab Emirates (accessed 2026-06-17)
  196. [196] Tier 2 Internet censorship in Turkey (Wikipedia) (accessed 2026-06-17)
  197. [197] Tier 2 Internet in Chile (accessed 2026-06-17)
  198. [198] Tier 2 Law No. 7253 (Social Media Law, 2020). Internet in Turkey (Wikipedia) (accessed 2026-06-17)
  199. [199] Tier 2 Investigatory Powers Act 2016, c. 25. Investigatory Powers Act 2016 (Wikipedia) (accessed 2026-06-15)
  200. [200] Tier 2 Israel National Cyber Directorate (INCD) (Wikipedia) (accessed 2026-06-17)
  201. [201] Tier 2 Privacy Protection Law, 1981, Sefer HaChukkim 1011, p. 128. Israel Privacy Protection Law 1981 (Wikipedia) (accessed 2026-06-17)
  202. [202] Tier 2 Israeli intelligence community (Wikipedia) (accessed 2026-06-17)
  203. [203] Tier 2 IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, G.S.R. 139(E). IT Rules 2021 (Wikipedia) (accessed 2026-06-17)
  204. [204] Tier 2 Kenya Finance Bill 2024 (Wikipedia) (accessed 2026-06-17)
  205. [205] Tier 2 Kenya Huduma Namba (Wikipedia) (accessed 2026-06-17)
  206. [206] Tier 2 Kenya protests 2024 (Wikipedia) (accessed 2026-06-17)
  207. [207] Tier 2 S. 1748, 118th Cong. (2023) (Kids Online Safety Act). Kids Online Safety Act (KOSA) (accessed 2026-06-16)
  208. [208] Tier 2 Geldwäschegesetz (GwG), BGBl. I 2008 S. 1690. Know-your-customer (KYC) requirements (accessed 2026-06-16)
  209. [209] Tier 2 Act on Interception of Communications, Act No. 67 of 1999. Lawful interception (Wikipedia) (accessed 2026-06-15)
  210. [210] Tier 2 Legality of cryptocurrency by country or territory (Wikipedia) (accessed 2026-06-17)
  211. [211] Tier 2 Loi n 2015-912 du 24 juillet 2015. Loi renseignement 2015 (accessed 2026-06-16)
  212. [212] Tier 2 Marco Civil da Internet, Lei No. 12.965, 23 April 2014. Marco Civil da Internet (Wikipedia) (accessed 2026-06-17)
  213. [213] Tier 2 Regulation (EU) 2023/1114 (MiCA). Markets in Crypto-Assets Regulation (MiCA) (accessed 2026-06-16)
  214. [214] Tier 2 Mass surveillance (accessed 2026-06-17)
  215. [215] Tier 2 Mass surveillance in Australia (Wikipedia) (accessed 2026-06-15)
  216. [216] Tier 2 Mass surveillance in India (Wikipedia) (accessed 2026-06-17)
  217. [217] Tier 2 Mexican war on drugs - Wikipedia (accessed 2026-06-17)
  218. [218] Tier 2 Military Counterintelligence Service (SKW, Poland) (accessed 2026-06-17)
  219. [219] Tier 2 Ministry of Communication and Digital Affairs (Wikipedia) (accessed 2026-06-17)
  220. [220] Tier 2 Ministry of Economy, Trade and Industry (Japan) (Wikipedia) (accessed 2026-06-15)
  221. [221] Tier 2 MIT (Turkey) (Wikipedia) (accessed 2026-06-17)
  222. [222] Tier 2 MyGovID - Wikipedia (accessed 2026-06-17)
  223. [223] Tier 2 National Communications Centre (South Africa) (accessed 2026-06-17)
  224. [224] Tier 2 National Intelligence Service Act, No. 28 of 2012. National Intelligence Service (Kenya) (Wikipedia) (accessed 2026-06-17)
  225. [225] Tier 2 National Intelligence Service Act, Act No. 4806 of 1994. National Intelligence Service (South Korea) (accessed 2026-06-16)
  226. [226] Tier 2 NetzDG (Netzwerkdurchsetzungsgesetz), BGBl. I 2017 S. 3352. NetzDG (Wikipedia) (accessed 2026-06-15)
  227. [227] Tier 2 Nigeria (accessed 2026-06-17)
  228. [228] Tier 2 Personal Data Act (Personopplysningsloven), LOV-2018-06-15-38. Norwegian Data Protection Authority (Datatilsynet) (Wikipedia) (accessed 2026-06-17)
  229. [229] Tier 2 Intelligence Service Act (Etterretningstjenesteloven), LOV-2024-04-12. Norwegian Intelligence Service (E-tjenesten) (Wikipedia) (accessed 2026-06-17)
  230. [230] Tier 2 Audiovisual Media Services Act (Kringkastingsloven), 2020 amendments. Norwegian Media Authority (Medietilsynet) (Wikipedia) (accessed 2026-06-17)
  231. [231] Tier 2 Criminal Procedure Act (Straffeprosessloven), Section 216a et seq.. Norwegian Police Service (Wikipedia) (accessed 2026-06-17)
  232. [232] Tier 2 NSO Group (Wikipedia) (accessed 2026-06-17)
  233. [233] Tier 2 Office of the Australian Information Commissioner (Wikipedia) (accessed 2026-06-15)
  234. [234] Tier 2 Bill C-63, 1st Sess, 44th Parl, Canada 2024. Online Harms Act (Bill C-63) (accessed 2026-06-16)
  235. [235] Tier 2 Online Safety Act 2023 (Wikipedia) (accessed 2026-06-15)
  236. [236] Tier 2 Operation Car Wash (Wikipedia) (accessed 2026-06-17)
  237. [237] Tier 2 Operation Rubicon / Crypto AG (Wikipedia) (accessed 2026-06-17)
  238. [238] Tier 2 POJK No. 27/POJK.03/2024 on Crypto Asset Trading. Otoritas Jasa Keuangan (Wikipedia) (accessed 2026-06-17)
  239. [239] Tier 2 Pegasus (spyware) (Wikipedia) (accessed 2026-06-17)
  240. [240] Tier 2 Personal Information Protection Act, Act No. 11150 of 2011. Personal Information Protection Act (South Korea) (accessed 2026-06-16)
  241. [241] Tier 2 Personal Information Protection Act, Act No. 19234 of 2023. Personal Information Protection Commission (South Korea) (Wikipedia) (accessed 2026-06-15)
  242. [242] Tier 2 Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5. PIPEDA (Personal Information Protection and Electronic Documents Act) (accessed 2026-06-16)
  243. [243] Tier 2 Police Security Service (PST) (Wikipedia) (accessed 2026-06-17)
  244. [244] Tier 2 Policia Nacional (Spain) - Wikipedia (accessed 2026-06-17)
  245. [245] Tier 2 Polizia di Stato (State Police) - Wikipedia (accessed 2026-06-17)
  246. [246] Tier 2 Privacy Act 2020 - Wikipedia (accessed 2026-06-17)
  247. [247] Tier 2 Public Security Investigation Agency (Wikipedia) (accessed 2026-06-15)
  248. [248] Tier 2 REAL ID Act of 2005, Pub. L. 109-13, 119 Stat. 302. REAL ID Act (accessed 2026-06-16)
  249. [249] Tier 2 RealMe - NZ government login (accessed 2026-06-17)
  250. [250] Tier 2 Reception and criticism of WhatsApp security and privacy features (Wikipedia) (accessed 2026-06-17)
  251. [251] Tier 2 RBI Circular DBR.No.BP.BC.104/08.13.102/2017-18 (April 6, 2018). Reserve Bank of India (Wikipedia) (accessed 2026-06-17)
  252. [252] Tier 2 Royal Canadian Mounted Police (RCMP) (accessed 2026-06-16)
  253. [253] Tier 2 Anti-Cyber Crime Law, Royal Decree No. M/17 of 2007. Saudi Arabia (accessed 2026-06-17)
  254. [254] Tier 2 Schengen Information System (Wikipedia) (accessed 2026-06-15)
  255. [255] Tier 2 Shin Bet (Israel Security Agency) (Wikipedia) (accessed 2026-06-17)
  256. [256] Tier 2 South Africa (accessed 2026-06-17)
  257. [257] Tier 2 South African Police Service (accessed 2026-06-17)
  258. [258] Tier 2 Ley 18/2023; Ley 13/2022. Spanish Data Protection Agency (AEPD) - Wikipedia (accessed 2026-06-17)
  259. [259] Tier 2 Loi n 2024-449 du 21 mai 2024 (SREN). SREN (Loi du 21 mai 2024) (accessed 2026-06-16)
  260. [260] Tier 2 Undang-Undang No. 17 Tahun 2011 tentang Intelijen Negara. State Intelligence Agency (Indonesia) (Wikipedia) (accessed 2026-06-17)
  261. [261] Tier 2 Financial Market Infrastructure Act (FMIA), SR 958.1; Banking Act, SR 952.0. Swiss Financial Market Supervisory Authority (FINMA) (Wikipedia) (accessed 2026-06-17)
  262. [262] Tier 2 Switzerland - European Union relations (Wikipedia) (accessed 2026-06-17)
  263. [263] Tier 2 Telecommunications (Security) Act 2021, c. 31. Telecommunications (Security) Act 2021 (Wikipedia) (accessed 2026-06-15)
  264. [264] Tier 2 Telecommunications Business Act, Act No. 86 of 1984; Provider Liability Limitation Act, Act No. 137 of 2001. Telecommunications in Japan (Wikipedia) (accessed 2026-06-15)
  265. [265] Tier 2 Teudat Zehut (Israeli identity card) (Wikipedia) (accessed 2026-06-17)
  266. [266] Tier 2 Ley 27.253, 2001 (Argentina wiretap law). Tor (anonymity network) (Wikipedia) (accessed 2026-06-17)
  267. [267] Tier 2 Tor (network) (Wikipedia) (accessed 2026-06-15)
  268. [268] Tier 2 Turk Ceza Kanunu, Law No. 5237 (2004), Articles 132-138. Turkish Criminal Code (Wikipedia) (accessed 2026-06-17)
  269. [269] Tier 2 Law No. 5490 on Population Services (2006). Turkish Identification Number (Wikipedia) (accessed 2026-06-17)
  270. [270] Tier 2 Law No. 2937 (2014); Law No. 6710 (2016). Turkish National Intelligence Organization (Wikipedia) (accessed 2026-06-17)
  271. [271] Tier 2 UAE Federal Decree-Law No. 34 of 2021 on Combating Rumors and Cybercrime, Article 9. United Arab Emirates (accessed 2026-06-17)
  272. [272] Tier 3 Access Now: Nigeria (accessed 2026-06-17)
  273. [273] Tier 3 Access Now: Saudi Arabia (accessed 2026-06-17)
  274. [274] Tier 3 Access Now: South Africa (accessed 2026-06-17)
  275. [275] Tier 3 Access Now: UAE (accessed 2026-06-17)
  276. [276] Tier 3 Derechos Digitales (accessed 2026-06-17)
  277. [277] Tier 3 EDRi (accessed 2026-06-16)
  278. [278] Tier 3 EDRi topic: Anonymity (accessed 2026-06-16)
  279. [279] Tier 3 Directive 2002/58/EC (e-Privacy Directive). EDRi: Tor and EDRi (accessed 2026-06-16)
  280. [280] Tier 3 Freedom on the Net 2024: China (accessed 2026-06-17)
  281. [281] Tier 3 Freedom on the Net 2024: Russia (accessed 2026-06-17)
  282. [282] Tier 3 Open Rights Group: encryption and anonymity (accessed 2026-06-16)
  283. [283] Tier 3 Paradigm Initiative (accessed 2026-06-17)
  284. [284] Tier 4 China's Cybersecurity Law Three Years On (accessed 2026-06-17)
  285. [285] Tier 4 Russia Internet Censorship (accessed 2026-06-17)
  286. [286] Tier 4 Russia Internet Censorship Explained (accessed 2026-06-17)
  287. [287] Tier 4 Russia's Digital Authoritarianism (accessed 2026-06-17)