Managing Conflicting Privacy Requirements

SkillDev tools

Guides managing conflicting privacy requirements across jurisdictions. Covers data localisation vs transfer freedom, consent standards variation, age thresholds, breach timelines, and resolution frameworks for incompatible obligations. Keywords: conflicting laws, data localisation, consent variation, age thresholds, resolution framework.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Managing Conflicting Privacy Requirements skill

What this skill tells your AI

The instructions your AI receives, as published by thomasmoreai/legal-skills-open in cross-jurisdiction/data-protection/skills/conflicting-laws-mgmt/SKILL.md and read by ahel’s review.

Overview

Organisations operating across multiple jurisdictions inevitably encounter situations where privacy requirements in different countries conflict, are incompatible, or create compliance tensions. These conflicts arise because privacy laws reflect different legal traditions, cultural values, and policy priorities. A structured resolution framework enables organisations to navigate these conflicts while maintaining defensible compliance positions in all jurisdictions.

Categories of Conflict

Category 1: Data Localisation vs Transfer Freedom

ConflictDetail
Localisation requirementChina PIPL Art. 40 requires CIIOs to store personal information within the PRC; India RBI circular requires payment data stored in India
Transfer freedomEU GDPR Art. 44-49 permits transfers with appropriate safeguards; Singapore PDPA Section 26 permits transfers with comparable protection
Resolution challengeAn organisation may need to store data locally while also making it available to a global headquarters

Resolution Framework for Zenith Global Enterprises:

ScenarioApproach
China CIIO data + EU HQ accessStore primary data in PRC; transfer processed copies via CAC-approved mechanism; maintain PRC as system of record
India payment data + Global TreasuryStore payment system data in India (RBI compliance); process copies transferred to Treasury with contractual safeguards
Cross-jurisdiction analyticsImplement federated analytics: run queries locally, aggregate results centrally; avoid moving raw personal data

Category 2: Consent Standards Variation

JurisdictionConsent Standard
EU (GDPR)Freely given, specific, informed, unambiguous; not required if other lawful basis applies
China (PIPL)Default basis; separate consent (单独同意) for five scenarios
Korea (PIPA)Prescriptive display requirements (font size, colour); separate consent for marketing
Brazil (LGPD)Standalone consent clause separate from contract terms; 10 alternative bases
India (DPDP)Free, specific, informed, unconditional, unambiguous; Consent Manager integration
Japan (APPI)Implied consent model for general processing; explicit for special care-required info

Conflict examples:

  • GDPR allows legitimate interest without consent; PIPL requires consent as default with no legitimate interest basis
  • LGPD separates consent from contract clauses; some jurisdictions permit integrated consent
  • Korea prescribes font size and display; other jurisdictions are principle-based

Resolution: Apply the most restrictive consent standard globally (separate, explicit, purpose-specific consent with clear display) as the harmonised baseline. Where a jurisdiction permits processing without consent (e.g., GDPR legitimate interest), document the jurisdiction-specific basis but maintain the consent infrastructure as a fallback.

Category 3: Age Thresholds for Children

JurisdictionAgeImplication
India (DPDP)Under 18All under-18 processing requires parental consent
Australia (2024)Under 18Children's code applies
EU (GDPR)Under 16 (lowerable to 13)Parental consent for ISS
China (PIPL)Under 14Parental consent + additional protections
Korea (PIPA)Under 14Legal representative consent
Thailand (PDPA)Under 10Parental consent

Conflict: Different age thresholds create operational complexity for global platforms.

Resolution: Apply the highest global threshold (18, from India DPDP) as the harmonised standard for all markets. This ensures compliance everywhere at the cost of stricter treatment in jurisdictions with lower thresholds. Where the highest threshold creates significant business impact, implement jurisdiction-specific age logic in the consent management platform.

Category 4: Breach Notification Timelines

JurisdictionTimelineTrigger
EU GDPR72 hoursRisk to rights and freedoms
Korea PIPA72 hours1,000+ individuals affected
India DPDP72 hours (draft)Likely harm
Brazil LGPD3 business daysRelevant risk or damage
Singapore PDPA3 days after assessment (30-day assessment window)Significant harm or 500+ individuals
Australia Privacy ActAs soon as practicable (30-day assessment)Likely serious harm
Japan APPI3-5 business days (preliminary)PPC-defined thresholds

Conflict: The 72-hour clock (EU/Korea/India) conflicts with the 30-day assessment window (Singapore/Australia).

Resolution: Implement a two-track notification process:

  1. Global fast track: Begin assessment immediately upon awareness; prepare notification within 72 hours for jurisdictions requiring it
  2. Assessment track: Continue assessment for up to 30 days for jurisdictions permitting it, but issue preliminary notification at 72 hours to the fast-track jurisdictions
  3. Content: Preliminary 72-hour notification may be updated as assessment continues

Category 5: Legitimate Interest Availability

JurisdictionLegitimate Interest Available
EU (GDPR)Yes — Art. 6(1)(f)
UK GDPRYes — Art. 6(1)(f)
Korea (PIPA)Yes — Art. 15(1)(6) (2023 amendment)
Brazil (LGPD)Yes — Art. 7, IX
Thailand (PDPA)Yes — Section 24(5)
China (PIPL)No
India (DPDP)No (legitimate uses under Section 7 are narrower)
Japan (APPI)No (use limitation approach)
Singapore (PDPA)No (consent + deemed consent model)

Conflict: An organisation relying on legitimate interest in the EU cannot use the same basis in China, India, or Singapore.

Resolution: For processing activities that rely on legitimate interest in some jurisdictions, maintain consent collection infrastructure as a parallel mechanism. In jurisdictions without legitimate interest, obtain consent or identify an applicable alternative basis. Document both bases in the processing register with jurisdiction-specific applicability.

Category 6: DPO Independence vs Organisational Structure

ConflictDetail
GDPR Art. 38(3)DPO cannot be dismissed or penalised for performing duties; must report to highest management
National employment lawsSome jurisdictions limit the enforceability of dismissal protections for senior employees
Multi-jurisdiction DPOA single global DPO may face conflicting reporting requirements across jurisdictions

Resolution: Appoint regional DPOs with local employment protections consistent with national law, reporting to a global Chief Privacy Officer. Each regional DPO holds the statutory DPO role for their jurisdiction while the global CPO provides strategic coordination.

Resolution Framework

Decision Tree for Conflicting Requirements

START: Identify the conflict
  |
  ├── Can a single harmonised standard satisfy all jurisdictions?
  |     |
  |     ├── YES → Apply the most stringent standard globally
  |     |
  |     └── NO → Are the requirements truly incompatible?
  |           |
  |           ├── YES → Implement jurisdiction-specific controls
  |           |     |
  |           |     └── Document: (a) the conflict, (b) the resolution,
  |           |         (c) the risk accepted in each jurisdiction
  |           |
  |           └── NO (tension but not incompatible) → Apply layered approach:
  |                 global baseline + jurisdiction-specific supplements
  |
  └── Record the resolution in the conflict register

Conflict Register Template

Conflict IDCategoryJurisdictionsDescriptionResolutionRisk AssessmentReview Date
CON-001Data localisationChina, India, EUCIIO data must stay in PRC but EU HQ needs accessLocal storage + processed copies transferred via CAC mechanismMedium — residual risk of CAC rejection on renewalMarch 2027
CON-002Consent standardsChina, EU, KoreaPIPL requires consent; GDPR permits legitimate interestDual-basis approach: consent in China/Korea, legitimate interest in EULow — consent infrastructure maintained globallyMarch 2027
CON-003Children's ageIndia (18), EU (16), Korea (14)Different parental consent thresholdsGlobal 18 thresholdLow — over-compliant in lower-threshold jurisdictionsMarch 2027
CON-004Breach timelineEU (72h), Singapore (30d assessment)Different notification clocksTwo-track: 72h preliminary + 30d full assessmentLow — preliminary notification satisfies fast-track jurisdictionsMarch 2027

Governance

ElementDetail
Conflict register ownerChief Privacy Officer
Review frequencySemi-annually or upon law change
Escalation pathCPO → General Counsel → Board Privacy Committee
External counselEngaged for novel conflicts requiring jurisdiction-specific legal opinion
DocumentationAll resolutions documented with legal analysis and risk assessment

Signals

GitHub stars
72
Forks
7
Last commit
Jul 2026
Advanced
Catalog kind
skill
Gateway key
conflicting-laws-mgmt
Source
github.com/thomasmoreai/legal-skills-open