Privacy Law Directory

How privacy laws, surveillance laws, MLATs, and intelligence alliances interact across 38 jurisdictions

← Back to Articles

About This Directory

A living directory covering 38 jurisdictions, last updated July 29, 2026. Each page covers surveillance laws, intelligence agencies, MLATs, data sharing agreements, data retention, cable infrastructure, age verification, encryption policy, and commercial surveillance procurement, not just data protection legislation. Organized around the alliances, conventions, and data-sharing frameworks that determine how intercepted communications and stored data actually move between governments: the signals-intelligence alliances (Five, Nine, and Fourteen Eyes, the Pacific SSPAC, and Europe’s Maximator), the Club de Berne and its separate Counter Terrorism Group, the EU law-enforcement frameworks (Europol, Schengen, Prüm), the mutual legal assistance treaties and conventions (bilateral MLATs, the 1959 European Convention, the Budapest Convention, and the US CLOUD Act), and the regional blocs (ASEAN, Mercosur, the Nordic-Baltic circle, and the Five Power Defence Arrangements).

Contrary to popular belief and heavy marketing, you are NOT protected by the country's privacy laws if you are foreign traffic to the service. Foreign traffic falls under surveillance laws, MLATs, and other data sharing agreements in every jurisdiction below. Think of jurisdictions like an attack surface, the more you add, the more possible MLATs and data sharing agreements you become subject to and these agreements and treaties are designed to simplify data requests and sharing.

You are also not necessarily protected by E2EE, either, because the data most requested is the metadata that cannot be encrypted.
(see Metadata Is Enough: Why Encrypted Email Still Tells Them Almost Everything with examples of it in action).

Nearly every nation here exempts its intelligence agencies from privacy laws when targeting foreigners. These exemptions, combined with alliances that let partner nations collect on each other’s populations and share results back, structurally bypass domestic protections. Commercial surveillance adds another layer: data brokers, IXP monitoring, and spyware vendors sell directly to governments without judicial oversight.

Why MLATs Matter

Mutual Legal Assistance Treaties (MLATs) let governments compel production of evidence located in another country’s jurisdiction. Country A asks Country B to obtain data and hand it back. The MLAT itself defines what can be requested and how, not the domestic privacy laws of either country.

The asymmetry: a French citizen whose data is held by a US company (Gmail, Microsoft, etc.) may have strong GDPR protections that would make it difficult for France to obtain that data domestically. But France can submit an MLAT request to the US DOJ, which compels the US company to produce the data under the terms of the treaty, routing around the stronger domestic standard entirely.

The reverse also works. US law enforcement can use MLATs to obtain data held abroad that might be harder to get domestically. The Fourth Amendment imposes warrant requirements, probable cause standards, and exclusionary rules. But if data is obtained via MLAT, US courts have generally held that the Fourth Amendment’s exclusionary rule doesn’t apply to evidence produced under treaty obligations, unless US agents were so involved that it was essentially a joint operation.

Corrections: updates@codamail.com.

United States

The United States is the lead nation of the Five Eyes and the core node of the Nine and Fourteen Eyes, of SSPAC, and of Five Eyes Plus; a member of the Quad; a party to the Budapest Convention (2007), to the OAS Inter-American mutual-assistance convention, and to the three near-universal UN assistance conventions (the 1988 Vienna drug convention, UNTOC, and UNCAC); and the hub of the global MLAT and CLOUD Act network, with reciprocal CLOUD Act agreements in force with the United Kingdom and Australia and an operational agreement with Europol. It runs warrantless global foreign collection under FISA Section 702 and Executive Order 12333. The CLOUD Act is designed to surpass MLATs in speed and compels US providers and partners to the Act to produce data anywhere it is located. The NSA taps submarine cables and internet backbones worldwide in partnership with many other countries. The US has no comprehensive privacy law, instead, a sector-specific patchwork (HIPAA, FERPA, GLBA, COPPA, ECPA), no data-retention mandate, and no encryption restrictions, with consumer protection left to an uneven set of state laws.

Five Eyes Alliance

The Five Eyes is the core anglophone signals intelligence alliance under the UKUSA Agreement (1946). Member nations share raw signals intelligence by default and can collect on each other’s citizens and share it back, a structure that critics argue functions as a mechanism to circumvent domestic legal restrictions on surveilling one’s own population.

Nine Eyes Alliance

The Nine Eyes extends the Five Eyes by four European nations who share signals intelligence as “third party” partners under the UKUSA framework. Unlike Five Eyes members, third-party partners are not automatically exempt from being targeted by NSA collection.

Fourteen Eyes Alliance (SIGINT Seniors Europe)

SIGINT Seniors Europe, commonly known as the Fourteen Eyes, adds five more nations to the Nine Eyes framework. The alliance was formed in 1982 during the Cold War and expanded after September 2001 to include counterterrorism cooperation.

European Union (Europol / Schengen / Prüm)

All EU member states are subject to the GDPR, the ePrivacy Directive, and the Law Enforcement Directive, but Article 2(2) exempts national security, an exemption every member state uses. On the surveillance side they are bound into a shared law-enforcement data-sharing architecture, Europol, the Schengen Information System, the Prüm biometric network, and the European Investigation Order, and their security services participate in the Club de Berne. The member states listed here are not part of any Eyes alliance; those that are (Denmark, France, and the Netherlands in the Nine Eyes; Germany, Belgium, Italy, Sweden, and Spain in the Fourteen Eyes) appear under those headings above.

Asia-Pacific Partners (SSPAC)

SIGINT Seniors of the Pacific (SSPAC) is the Asia-Pacific counterpart to SIGINT Seniors Europe. Founded by the Five Eyes nations alongside South Korea, Singapore, and Thailand, later joined by France (2013) and India (2008). Members share counterterrorism intelligence through the CRUSHED ICE secure network. Like Nine Eyes third-party partners, SSPAC members are not automatically exempt from being targeted by NSA collection.

Other Partners and Transit States

The jurisdictions below are not members of the numbered Eyes alliances, SSPAC, or the EU, but each participates in intelligence data sharing, has its traffic transit through partner nations’ cable-tapping infrastructure, or maintains its own foreign surveillance capabilities with few restrictions on non-citizen targeting. The recurring pattern across this directory applies here as well: privacy laws protect domestic populations while foreign traffic faces minimal legal barriers to interception.

1959 European Convention on Mutual Assistance

The European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30) is the general framework for cross-border criminal evidence in Europe. As of 2026 it has 51 parties: all 46 Council of Europe member states plus five non-members, Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation (which remains a party despite its 2022 expulsion from the Council of Europe).

Budapest Convention on Cybercrime

The Budapest Convention on Cybercrime (2001, ETS 185) provides for the expedited preservation and cross-border disclosure of stored computer and subscriber data, the category of data an email or messaging provider holds. As of 2026 it has 82 parties: 45 Council of Europe member states (every member except Ireland, which signed but has not ratified) plus 37 non-member states across the Americas, Africa, and the Asia-Pacific, among them the United States, Canada, Australia, Japan, Brazil, and Israel.

Global Mutual Assistance Conventions (UN and OAS)

Three near-universal United Nations conventions each carry their own mutual-legal-assistance machinery, so evidence can move between two countries that share no bilateral MLAT and no regional convention at all. The 1988 Vienna Convention (the UN Convention against Illicit Traffic in Narcotic Drugs and Psychotropic Substances) obliges its 192 parties to provide the widest measure of mutual assistance in drug-trafficking investigations, including banking, financial, and business records. The UNTOC (UN Convention against Transnational Organized Crime, the “Palermo Convention,” 2000) functions through its Article 18 as a de facto worldwide MLAT for organized-crime cases, spanning 193 parties. The UNCAC (UN Convention against Corruption, 2003) does the same for corruption offences across 192 parties, including tracing, freezing, and confiscation of assets. Like Interpol and the Egmont Group, these networks are effectively universal, so no roster is given; the practical point is that a “no MLAT with that country” assurance says nothing about drug, organized-crime, or corruption investigations, where these conventions supply the treaty basis on their own.

The OAS Inter-American Convention on Mutual Assistance in Criminal Matters (1992, in force 1996) is the regional instrument of the Americas, with 27 parties: Antigua and Barbuda, Argentina, the Bahamas, Bolivia, Brazil, Canada, Chile, Colombia, Costa Rica, Dominica, Ecuador, El Salvador, Grenada, Guatemala, Guyana, Honduras, Jamaica, Mexico, Nicaragua, Panama, Paraguay, Peru, Suriname, Trinidad and Tobago, the United States (2001), Uruguay, and Venezuela; status is tracked in the OAS signatures chart (A-55). The United States, Canada, and Brazil are the parties covered in this directory.

Council of Europe

The Council of Europe is a 46-member human-rights and rule-of-law organisation, distinct from the European Union. It is the parent body of the two mutual-assistance conventions above, the 1959 Convention and the Budapest Convention, both concluded under its treaty system. It is also the home of the European Convention on Human Rights and the European Court of Human Rights in Strasbourg, which has repeatedly found mass-surveillance regimes in breach of the Convention (among them the United Kingdom’s bulk interception in Big Brother Watch and Sweden’s FRA cable-tapping in Centrum för Rättvisa). Every European jurisdiction in this directory is a member; the Russian Federation was expelled in 2022. Non-European parties to its conventions, such as the United States, Israel, Japan, and Brazil, are not members.

Maximator (European SIGINT)

Maximator is a European signals-intelligence alliance kept secret from 1976 until its disclosure in 2020, comprising Denmark, France, Germany, the Netherlands, and Sweden. Members pooled intercepted communications, including intelligence derived from the rigged Crypto AG cipher devices. All five are listed under the Nine and Fourteen Eyes above.

Club de Berne and the Counter Terrorism Group

The Club de Berne, founded in 1969, is the forum of the heads of the domestic intelligence and security services of the 27 EU member states together with Norway and Switzerland. It is a broad, all-source intelligence-sharing body for the strategic direction of European intelligence cooperation, not a counterterrorism-specific one. The Counter Terrorism Group (CTG) is a separate offshoot, created in September 2001 after the 11 September attacks and dedicated specifically to sharing terrorism intelligence; its membership overlaps the Club’s and additionally includes the United Kingdom. Since 2016 the two have run a joint operational platform in The Hague with a common database and real-time information system. Every EU member state on this page takes part in the Club de Berne, along with Norway and Switzerland; the CTG adds the UK.

A separate and older channel is the Kilowatt Group, a counter-terrorism intelligence-sharing club dating to the early 1970s that exchanges information among Western services, reported as some 17 European countries and the United States, over the “Kilowatt” encrypted telegram system. Its significance in this directory is Israel: not a Club de Berne or CTG member, Israel participates in Kilowatt, giving it a standing counter-terrorism exchange with the European services outside the EU frameworks.

Europol

Europol is the EU Agency for Law Enforcement Cooperation, constituted by the 27 EU member states. It also maintains operational cooperation agreements (permitting personal-data exchange and liaison officers) with seventeen non-EU states, Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States, with Denmark participating under a separate agreement owing to its Justice and Home Affairs opt-out. Because Europol in turn cooperates with the FBI, data routed through it can flow onward to US law enforcement.

Schengen Information System

The Schengen Area comprises twenty-nine states whose police share real-time alerts through the Schengen Information System: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland. The four non-EU members (Iceland, Liechtenstein, Norway, and Switzerland) participate as associated states; Ireland and Cyprus are EU states outside the Schengen Area.

Prüm Framework

The Prüm framework automates cross-border exchange of DNA profiles, fingerprints, and vehicle-registration data. It binds all 27 EU member states together with the four non-EU Schengen-associated states (Iceland, Liechtenstein, Norway, and Switzerland), thirty-one in all; the Prüm II Regulation (2024) extends it to facial images and police records.

Regional Frameworks

Beyond the SIGINT alliances, several regional blocs move intelligence and evidence across borders. Their members appear under their biggest alliance above; the rosters are:

Strategic Blocs (BRICS, SCO, Quad)

Several jurisdictions here also belong to strategic and political blocs that carry security and intelligence dimensions, though not the formal mutual-assistance machinery of the frameworks above:

Cable Infrastructure and Interception Points

The physical layer beneath the alliances: the documented submarine-cable and backbone taps, internet-exchange interception, and cable chokepoints through which cross-border traffic is collected. Programs are named where public disclosure (largely the Snowden documents and subsequent court findings) has identified them.

Backbone and Submarine-Cable Taps

Internet Exchange Point (IXP) Taps

Cable Chokepoints and Landing Hubs

Strategic points where cross-border traffic is physically concentrated: Crete (Greece, the Europe-Middle East-Asia hub), Sicily (Italy, the Mediterranean hub), Sines and Carcavelos (Portugal, a three-continent Atlantic hub), the Strait of Gibraltar (Spain), the Strait of Malacca (Malaysia), and the Baltic cables C-Lion1 and BCS East-West Interlink (Finland and Estonia), repeatedly cut or sabotaged since 2023.

Directory Information

This directory covers 41 pages across 38 country jurisdictions, including dedicated coverage of US federal and state privacy laws, the EU framework, and international partners. It is maintained by CodaMail as a public resource for understanding the global privacy and surveillance landscape. Pages are updated as new legislation, enforcement actions, and intelligence disclosures warrant revision.

This directory grew from The Myth of Jurisdictional Privacy, through Your Phone is a Military Target and the Data Broker Directory (1,700+ entities across 17 categories).

← Back to Articles