The European General Data Protection Regulation (GDPR) has had a major impact on data collection and processing practices. It has also challenged interaction design aiming to support the effectiveness of data owners' rights, their informed decisions, and their actions regarding how personal information is used by companies, governments, and others. Similar legislation has been issued in various non-European countries, which means that, in this respect, the HCI community has an important role to play for users all over the world. This paper presents the conclusions of a contrastive study with four major e-commerce websites in Portugal, where data protection law has been effective since 2018, and four analogs in Brazil, where the national Data Protection Law (DPL) has been sanctioned but will only be effective in 2020. The purpose of the study is to examine the pre-legislation to post-legislation evolution in the design of interaction for communication and action about personal data protection matters, so as to anticipate some of the threats and opportunities ahead of us. Using concepts and elements of Semiotic Engineering methods and techniques, we found that, within the scope of this study, GDPR seems to have had little impact on what European users can do and experience online, compared to pre-DPL Brazilian users. We discuss some of the possible reasons for this and conclude with thoughts on the role of interaction design in empowering data owners for this new regulation era.