Comparative Law / International

Surveillance Law Around the World

Ten jurisdictions, one comparison table, and the handful of legal design choices — judicial sign-off, bulk vs. targeted collection, mandatory decryption, notification and redress — that actually determine how much protection a person has, wherever they are.

Why compare like this. "Does country X spy on its citizens?" is the wrong question — nearly every state with the technical capacity does, to some degree. The question that actually predicts how much protection an individual has is how the power is structured. This page compares jurisdictions along five recurring axes:

Every entry below is a snapshot, sourced from primary legislation, court judgments, and specialist legal reporting — see Sources & Methodology at the bottom before relying on anything here as current law.

Comparison Table United Kingdom United States Germany France European Union Australia China Russia India South Africa Cross-Border Sharing Synthesis Sources

At a Glance

Jurisdiction Core Legal Basis Bulk Collection Authorization Standing Oversight Landmark Reform / Ruling
United Kingdom Investigatory Powers Act 2016, as amended 2024 Yes — bulk interception & bulk personal dataset warrants "Double lock": Secretary of State + Judicial Commissioner IPCO + Investigatory Powers Tribunal Big Brother Watch v UK (ECtHR, 2021); IPA (Amendment) Act 2024
United States FISA 1978 + FISA Amendments Act §702 + Executive Order 12333 Yes — §702 upstream/PRISM; unrestricted under EO 12333 abroad FISA Court for §702; none independent for EO 12333 FISA Court + PCLOB (advisory only) Carpenter v. United States (2018); USA FREEDOM Act 2015 ended bulk §215 metadata program
Germany Basic Law Art. 10 + G10 Act + BND Act (2021 reform) Yes — foreign-foreign network surveillance by the BND G10 Commission (domestic); weaker independent panel for BND foreign-foreign G10 Commission + Independent Oversight Council (post-2021) BVerfG ruling, 19 May 2020: BND foreign surveillance unconstitutional → 2021 reform
France Intelligence Act 2015 (loi relative au renseignement) Yes — algorithmic "black box" metadata scanning Prime Minister authorizes; CNCTR gives prior (non-binding) opinion CNCTR First EU state to legalise algorithmic bulk metadata scanning (2015, repeatedly extended)
European Union Charter of Fundamental Rights Arts. 7 & 8; national security reserved to member states Varies by member state; CJEU sets outer limits N/A at EU level — CJEU case law is the real backstop Court of Justice of the EU Digital Rights Ireland (2014); Schrems I (2015) / II (2020); La Quadrature du Net (2020)
Australia TIA Act 1979 + TOLA 2018 + SLAID Act 2021 Mandatory metadata retention (2015) + content via warrant Issuing authority/Attorney-General; not always a judge Commonwealth Ombudsman + IGIS + INSLM TOLA 2018 (compelled decryption assistance); SLAID Act 2021 (data disruption/account takeover/network activity warrants)
China National Intelligence Law 2017 (Art. 7) + Cybersecurity Law 2017 + Data Security Law 2021 Yes, by design — no meaningful statutory limit Internal party/state approval only None independent Art. 7 codifies a legal duty for all citizens/organisations to "support, assist and cooperate" with state intelligence work
Russia SORM (since the 1990s) + Yarovaya Law 2016 + Sovereign Internet Law 2019 Yes — direct FSB access to network infrastructure None independent Roskomnadzor is the regulator, not a check on the security services Yarovaya Law compels decryption keys or blocking; 2019 law mandates DPI equipment nationwide
India IT Act 2000 §69 + IT Rules 2021 + DPDP Act 2023 Yes — directed interception + mandatory traceability of message originators Executive (Home Secretary-level); reviewed by an internal review committee, not a court Executive-internal Review Committee; no independent judicial tribunal 2021 Pegasus Project revelations; DPDP Act 2023 broadly exempts government agencies
South Africa RICA 2002, as amended following 2021 ruling Bulk interception declared unlawful in 2021 Designated judge, with independence safeguards added post-2021 Designated judge + evolving independent oversight AmaBhungane Centre v Minister of Justice (Constitutional Court, 4 Feb 2021)

Deep Dives

United Kingdom

Investigatory Powers Act 2016, as amended by the Investigatory Powers (Amendment) Act 2024

Authorization: Double lock Bulk powers: Yes Oversight: IPCO + IPT Notification: None general

The IPA 2016 (nicknamed the "Snoopers' Charter" by critics) consolidated and placed on a single statutory footing what RIPA 2000 had covered piecemeal: bulk interception, bulk acquisition of communications data, bulk equipment interference (government hacking), and bulk personal datasets (BPDs). Its headline safeguard is the "double lock": a warrant needs sign-off from a Secretary of State (or, for matters devolved to Scotland, Scottish Ministers) and approval from an independent Judicial Commissioner before it takes effect.

The Investigatory Powers (Amendment) Act 2024 extended the regime rather than narrowing it: intelligence services can now access bulk personal datasets held by third parties under a dedicated warrant category, subject to a lighter-touch regime for datasets assessed as carrying "low or no" expectation of privacy (e.g. some public/commercial datasets), and the Act created a new power to compel telecoms and tech operators to notify the government before rolling out changes to their services that might affect lawful-access capability.

United States

FISA 1978 · FISA Amendments Act 2008 §702 · Executive Order 12333 · USA FREEDOM Act 2015

Authorization: FISC (§702) / none (EO 12333) Bulk powers: Yes Oversight: FISC + PCLOB (advisory) 4th Amendment: Domestic only

US surveillance law runs on two tracks that rarely meet. Domestically, the Fourth Amendment and statutes like the Stored Communications Act set a warrant-based baseline, sharpened by Carpenter v. United States (2018), where the Supreme Court held that historical cell-site location data carries a reasonable expectation of privacy and generally requires a warrant. For foreign intelligence, FISA created a specialised, secret court (the FISA Court, or FISC) that authorizes surveillance of "agents of a foreign power" — expanded by the 2008 FISA Amendments Act's Section 702, which allows warrantless collection of foreign targets' communications where a US company is compelled to assist (the legal basis for programs publicly confirmed by the 2013 Snowden disclosures, including PRISM and upstream collection).

Outside FISA's reach entirely sits Executive Order 12333 (1981), which governs intelligence collection conducted overseas against non-US persons — no FISA Court, no warrant requirement, governed by internal executive branch procedures rather than judicially-reviewable statute. The 2001 PATRIOT Act's Section 215 enabled bulk domestic telephone metadata collection, which the Second Circuit found unlawful in ACLU v. Clapper (2015); Congress replaced it with the narrower USA FREEDOM Act 2015, ending the NSA's direct bulk-metadata database.

Germany

Basic Law Art. 10 · G10 Act · BND Act, as reformed 2021

Authorization: G10 Commission Bulk powers: Yes (foreign-foreign) Oversight: G10 Commission + new Council Redress: Weak for non-Germans

Germany has arguably the strongest constitutional privacy tradition among major democracies, rooted in the Federal Constitutional Court's 1983 census-case ruling establishing a standalone right to "informational self-determination." That tradition collided with the foreign intelligence service's (BND) practices in a landmark 19 May 2020 ruling: the Constitutional Court (Bundesverfassungsgericht) held that the BND's mass surveillance of foreign-foreign telecommunications — monitoring traffic between two non-Germans entirely outside Germany — was still bound by Basic Law fundamental rights, including press freedom, because Germany's constitution protects against German state interference regardless of the target's nationality or location.

The Bundestag had until the end of 2021 to fix the law; the resulting 2021 BND Act reform lets the agency continue monitoring entire foreign-foreign telecommunications networks for material relevant to German security or foreign policy, now under a newly created independent oversight council — but notably, the reform did not create statutory standing rights, meaning affected non-German individuals still have a limited practical path to challenge surveillance in court even though the constitutional principle now formally protects them.

France

Intelligence Act 2015 (loi relative au renseignement)

Authorization: Prime Minister Bulk powers: Yes (algorithmic) Oversight: CNCTR (advisory) First-of-kind: "Black box" scanning

France was the first EU state to put bulk algorithmic surveillance on a statutory footing. Under the 2015 Intelligence Act, intelligence services can require operators to install "black boxes" on their networks that scan metadata (not content) in bulk, using algorithms designed to flag patterns associated with terrorist threats. Authorization runs through the Prime Minister's office rather than a court; the CNCTR (Commission nationale de contrôle des techniques de renseignement) — an independent administrative authority created by the same 2015 Act — gives a prior opinion, but that opinion is not binding, and the Prime Minister can proceed over CNCTR's objection subject only to the possibility of after-the-fact challenge before the Conseil d'État.

The algorithmic-scanning provisions were originally time-limited and have been repeatedly extended rather than allowed to lapse, a pattern common to "temporary" counter-terrorism powers across several European jurisdictions.

European Union

Charter of Fundamental Rights Arts. 7 & 8 · GDPR/ePrivacy · CJEU case law

Authorization: Set by member states Real backstop: CJEU National security: Reserved to states

The EU itself does not run surveillance programs — national security is explicitly reserved to member states under the EU treaties — but the Court of Justice of the European Union (CJEU) has become the most consistently aggressive judicial check on bulk surveillance of any supranational body, using data protection and privacy provisions in the Charter of Fundamental Rights to strike down measures member states or the EU institutions themselves had adopted.

In Digital Rights Ireland (2014), the CJEU invalidated the EU's Data Retention Directive outright for its indiscriminate scope. In Schrems I (2015) and Schrems II (2020), brought by Austrian privacy activist Max Schrems, the Court twice struck down the EU's mechanisms for transferring personal data to the United States (Safe Harbour, then Privacy Shield) specifically because US surveillance law — chiefly Section 702 FISA and EO 12333 — didn't offer EU citizens protections the Court judged "essentially equivalent" to EU law. The European Commission's replacement, the EU-US Data Privacy Framework, took effect via adequacy decision on 10 July 2023, adding a redress mechanism and a "necessary and proportionate" limitation on US signals intelligence access to EU data — but privacy group noyb (founded by Schrems) has already signalled further legal challenges, and a first challenge to the Framework was rejected by the EU General Court in 2025, though additional challenges are expected.

Australia

Telecommunications (Interception and Access) Act 1979 · TOLA 2018 · SLAID Act 2021

Authorization: Not always a judge Decryption: Compellable No bill of rights

Australia has no constitutional bill of rights and no general constitutional privacy protection, which makes its surveillance regime one of the most expansive among comparable democracies almost by default. The 2018 Telecommunications and Other Legislation Amendment (Assistance and Access) Act ("TOLA") — sometimes called the "anti-encryption law" — lets agencies issue Technical Assistance Requests, Technical Assistance Notices, and Technical Capability Notices compelling communications providers to help law enforcement access data, up to and including building new capabilities, subject to a bar on requiring providers to introduce a "systemic weakness" (a term that has itself been criticised as poorly defined).

The 2021 Surveillance Legislation Amendment (Identify and Disrupt) Act ("SLAID") went further, creating three new warrant types: data disruption warrants (letting the AFP modify, add, copy, or delete data to frustrate criminal activity), network activity warrants (collecting data from a network used by a criminal network), and account takeover warrants (letting agencies take control of a person's online account). Oversight is split between the Commonwealth Ombudsman, the Inspector-General of Intelligence and Security, and the Independent National Security Legislation Monitor; all three SLAID powers carry a five-year sunset clause subject to review.

China

National Intelligence Law 2017 · Cybersecurity Law 2017 · Data Security Law 2021

Authorization: Internal only Independent oversight: None Judicial redress: None

China's framework is the clearest counter-example to the judicial-authorization model used elsewhere on this page, not as an enforcement gap but by design. Article 7 of the 2017 National Intelligence Law states that "any organization or citizen shall support, assist, and cooperate with state intelligence work" — a broad, legally codified compulsion rather than a narrowly scoped power subject to case-by-case authorization. The 2017 Cybersecurity Law adds real-name registration requirements for internet services and data-localization mandates; the 2021 Data Security Law extends state access and classification requirements to data processing generally.

There is no independent judiciary empowered to review intelligence and security decisions, no equivalent of a FISA Court or Judicial Commissioner, and no public complaints tribunal comparable to the UK's IPT. Combined with the Great Firewall's content-filtering infrastructure and social-credit-linked identity systems, the result is a surveillance architecture where the legal question is less "was this authorized correctly" and more "is there any legal space outside the state's reach" — for most practical purposes, there isn't.

Russia

SORM · Yarovaya Law 2016 · Sovereign Internet Law 2019

Authorization: Direct FSB access Decryption: Mandatory or blocked Data retention: 6mo content / 3yr metadata

SORM (System for Operative Investigative Activities), in place in various forms since the 1990s, requires Russian ISPs and telecoms operators to install government-controlled interception equipment giving the FSB direct technical access to network traffic — structurally, permission is built into the infrastructure rather than granted case by case. The 2016 "Yarovaya Law" (part of a broader anti-terrorism package) layered mandatory data retention on top: communications content for six months, metadata for three years, with providers compelled to assist the FSB in decrypting communications — and messaging services that refuse to hand over decryption keys face being blocked outright.

The 2019 Sovereign Internet Law added a further layer of state control over the network itself, requiring ISPs to install deep packet inspection (DPI) equipment capable of auto-blocking banned content, monitoring cross-border traffic, and — under a vaguely defined "crisis" trigger — letting the state regulator Roskomnadzor take direct control of routing. There is no independent body positioned to check the security services' use of any of this; Roskomnadzor is the implementing regulator, not an oversight check on state power.

India

IT Act 2000 §69 · IT Rules 2021 · Digital Personal Data Protection Act 2023

Authorization: Executive (Home Secretary) Judicial review: None 2021: Pegasus Project

Interception in India runs through Section 69 of the IT Act 2000, which lets the government direct interception, monitoring, or decryption of information on broad public-interest and security grounds. Authorization sits with a Home Secretary-level official and is reviewed only by an internal Review Committee composed of executive-branch officials — there is no independent judicial tribunal in the chain at all, a structural gap that puts India's authorization model closer to China's or Russia's than to the judicial-sign-off models used in the UK or Germany, despite India's status as a parliamentary democracy with an active constitutional court.

The 2021 IT Rules added a mandatory "traceability" requirement for large messaging platforms — the ability to identify the first originator of a message on demand — which critics argue is difficult to satisfy without weakening end-to-end encryption. The 2021 Pegasus Project revelations, which found evidence of NSO Group spyware associated with numbers belonging to journalists, opposition politicians, and activists in India among many other countries, intensified scrutiny of this framework, though it produced no comprehensive statutory reform. The Digital Personal Data Protection Act 2023, India's first general data protection statute, broadly exempts government agencies from many of its obligations on national-security and public-interest grounds.

South Africa

RICA 2002, as amended following AmaBhungane v Minister of Justice (2021)

Authorization: Designated judge Bulk powers: Ruled unlawful, 2021 Notification: Now required

South Africa is the clearest example on this page of courts actually rolling a surveillance regime back rather than ratifying its expansion. The case began after investigative journalist Sam Sole, of the amaBhungane Centre for Investigative Journalism, discovered his own communications with a prosecutor investigating former president Jacob Zuma had been intercepted. The resulting challenge to RICA (the Regulation of Interception of Communications Act 2002) succeeded first in the Pretoria High Court in 2019, then at the Constitutional Court on 4 February 2021.

The Constitutional Court found RICA unconstitutional in five distinct respects: no post-surveillance notification to the target, no guaranteed independence for the "designated judge" who approves interception, no safeguards for ex parte (one-sided) applications, no rules governing how intercepted data is handled afterward, and no special procedure for surveilling journalists or lawyers. Separately and more sweepingly, the Court found that bulk interception by the state's National Communications Centre had no lawful basis at all and ordered it stopped. Parliament was given time to fix the specific RICA defects; the ruling stands as one of the only examples of a top court halting an operational bulk-collection program outright, rather than narrowing the law that might someday authorise one.

Cross-Border Sharing: Where Domestic Law Stops Mattering

Five Eyes / UKUSA Agreement. The signals-intelligence-sharing arrangement between the US, UK, Canada, Australia, and New Zealand dates to a 1946 agreement, publicly acknowledged only in 2010. It is not itself a surveillance-authorizing law in any member country — it's a data-sharing arrangement layered on top of each country's own domestic legal authority. The long-standing controversy is the "surveillance-sharing" concern: whether one Five Eyes member can obtain data on another member's citizens that its own domestic law would have restricted, simply by asking a partner agency to collect it instead.

The CLOUD Act (US, 2018). Lets US law enforcement compel US-based providers to produce data they control regardless of where in the world it's physically stored, superseding the earlier rule that treated overseas-stored data as outside a US warrant's reach. It also created a framework for bilateral "executive agreements" letting vetted foreign governments request data directly from US providers, bypassing the slow Mutual Legal Assistance Treaty (MLAT) process — the UK-US CLOUD Act Agreement, the first of these, entered into force in 2022.

The EU-US Data Privacy Framework (2023). Covered above under the EU section — the current legal basis for routine commercial data flows from the EU to the US, built specifically to survive the surveillance-law objections that sank its two predecessors.

Synthesis: What Actually Predicts Protection

Laid side by side, the ten jurisdictions above sort less by "democracy vs. authoritarian state" than by five structural design choices:


Sources & Methodology

This page draws on primary legislation (official sources including legislation.gov.uk, legislation.gov.au, and the Federal Register of Legislation), court judgments (the UK IPT/ECtHR, the German Bundesverfassungsgericht, the CJEU, the South African Constitutional Court, and the US Supreme Court), regulator and oversight-body publications, and reporting/analysis from Privacy International, the Electronic Frontier Foundation, IAPP, and specialist legal publishers (DLA Piper, Freshfields, and others), current as of July 2026.

Surveillance law changes frequently. Treat every provision on this page as a snapshot, not a live legal reference — verify current text via the primary sources above before relying on anything here for a legal, safety, or compliance decision. Corrections are welcome via the contact channels listed elsewhere on the site.