Data protection regimes across jurisdictions share a common structure, with significant differences in detail.
Lawful basis for processing — consent, contract, legal obligation, vital interests, public task, or legitimate interests balanced against the individual’s rights. Consent is the weakest basis in employment contexts because it is not freely given.
Transparency. Notices at collection, describing purposes, recipients, retention and rights.
Purpose limitation and minimisation. Data collected for specified purposes and not further processed incompatibly, and limited to what is necessary.
Individual rights. Access, rectification, erasure, restriction, portability and objection, with response deadlines.
Security appropriate to the risk, and breach notification to regulators and, where risk is high, to individuals, on short deadlines.
Transfers out of the jurisdiction requiring an adequacy determination, standard contractual clauses with a transfer impact assessment, or another mechanism.
Accountability. Records of processing, impact assessments for high-risk processing, a data protection officer where required, and processor agreements with prescribed terms.
Enforcement. Administrative fines calculated by reference to global turnover in several regimes, plus individual claims.
Practical approach. Build to the strictest applicable standard and document the analysis; operating to different standards by jurisdiction is unmanageable at scale.