WEAR YOUR POSITION.
Shipping & returnsLinkedIn
PRIVACYAF
PRIVACYAF / GLOBAL SOURCE DESK

Privacy crosses borders.
Your research should too.

Official sources. Local context. Better questions. Explore privacy and AI resources, select the ones relevant to your work and take a research brief into the next conversation.

7 source pathways6 regionsReviewed October 6, 2026

Find your starting point.

7 resources shown · curated starting points, not a complete legal inventory

European Union / EEAData protection

GDPR guidance and decisions

European Data Protection Board · Official document collection

Find guidance, opinions and decisions from the EDPB. Check each document’s status and scope before relying on it.

Take into practice

Which processing activity and territorial scope are you assessing?

United KingdomAI

AI and data protection

Information Commissioner’s Office · Regulator guidance

Guidance on data protection questions raised by AI. The ICO flags review following the Data (Use and Access) Act; check current text and commencement information.

Take into practice

What personal data enters the system, and how will you assess its effects on people?

SingaporeAI

Personal data in AI recommendation and decision systems

Personal Data Protection Commission · Advisory guidelines

An official starting point for researching personal data use in AI recommendation and decision systems in Singapore.

Take into practice

What is the system recommending or deciding, and what personal data supports it?

BrazilCross-border transfers

International transfer mechanisms under the LGPD

Agência Nacional de Proteção de Dados · Regulator explanation of regulation

ANPD explains mechanisms under Resolution 19/2024, including contractual clauses and adequacy decisions. Confirm the applicable mechanism and current decisions.

Take into practice

Who exports and receives the data, and which transfer mechanism supports the actual flow?

South AfricaData protection

Prior authorisation under POPIA

Information Regulator · Regulator guidance

Guidance for responsible parties processing information subject to prior authorisation under POPIA. Read the linked guidance for conditions and procedure.

Take into practice

Does the planned activity fall within a category requiring prior authorisation?

Australia / Commonwealth agenciesPrivacy governance

Privacy Officer Toolkit

Office of the Australian Information Commissioner · Government agency toolkit

Practical resources for privacy officers in Australian Government agencies. Its agency context matters; do not assume every requirement applies to private organisations.

Take into practice

Who owns privacy review, and when does that review enter the project lifecycle?

United States / voluntary frameworkAI

Generative AI risk management profile

National Institute of Standards and Technology · Voluntary risk management resource

A generative AI companion to the NIST AI Risk Management Framework. A risk framework is not a determination of legal compliance.

Take into practice

What evidence will show that your risk controls work in the intended use?

THE PEOPLE BEHIND THE WORK

Your region belongs in the conversation.

This desk is a starting collection. It does not yet cover every jurisdiction or language. Help strengthen it with an official source, a practical question or a perspective from your work.

Contribute a perspective

From research to action

Build an AI boundary briefInvestigate a surveillance claimRead the PrivacyAF DispatchDiscuss privacy around the world