No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Where the CCPA and GDPR Overlap and Diverge

An Illustrated Comparison of the Regulations

by Felix Sebastian
November 14, 2019
in Data Privacy
businessman touching virtual data shield

Before the CCPA becomes law on January 1, 2020, compliance officers worldwide (not just in California or the U.S.) need to be sure their companies are compliant. Are steps taken toward GDPR compliance sufficient? Termly’s Felix Sebastian explores the differences between the regulations.

Since the General Data Protection Regulation (GDPR) took force, businesses have collectively spent billions of dollars and “hundreds of years of human time” on compliance efforts. These numbers look excessive at first glance, but with the GDPR supervisory authorities handing out multimillion-dollar fines to Google and other corporate giants this year, investing in prevention measures is cheaper than coughing up 4 percent of revenue.

Data protection officers and consumers alike are only just adjusting to this new era of data privacy laws, but another major regulation — the California Consumer Privacy Act (CCPA) — is awaiting its turn to go live on January 1, 2020.

Knowing how the CCPA and the GDPR differ (and are similar) is crucial to effectively prepare for upcoming CCPA compliance challenges. Here’s an infographic to help you get started on this research.

differences between CCPA and GDPR
Infographic courtesy of Termly

While the infographic compares the fundamentals of the GDPR and the CCPA, here are a few more similarities and differences worth noting:

Extraterritoriality — Who’s Covered?

Both the GDPR and the CCPA are extraterritorial in their scope. This means that while these two laws are based in the European Union (EU) and the U.S. state of California (CA), the laws still apply to businesses worldwide that target EU* and California residents, respectively.

Given the transnational nature of data and businesses in this internet age, extraterritoriality is a standard component in new privacy laws around the world, such as those in Thailand and Brazil.

Personal Data — What’s “Personal?”

At the core of both the GDPR and the CCPA lies the protection of personal data. However, the two laws differ in how they define “personal;” these distinctions in phrasing, though minor, have practical implications for businesses.

The GDPR uses the term “personal data” and defines it as “information that relates to an identified or identifiable individual.”

In contrast, the CCPA uses the term “personal information” and defines it as “information that identifies, relates to, describes, is capable of being associated with or could reasonably be linked, directly or indirectly, with a particular consumer or household.”

The CCPA’s use of “reasonably” in its definition provides more room for interpretation. In practice, this means that, for example, hashed data might not be deemed “personal” under the CCPA. We’ll have to wait and see how the interpretations of the enforcement agencies, businesses and consumers play out in the months following the CCPA taking effect.

Rights — What’s Provided?

Both the GDPR and the CCPA entitle their subjects to know what personal information is collected from them (and whether and with whom it’s shared), to access this information and to request that it be erased.

Specifically, the GDPR gives EU* consumers eight rights over their personal data. Those include the right to:

  1. Know
  2. Access
  3. Rectify
  4. Erasure
  5. Restrict (processing)
  6. Data portability
  7. Object (to direct marketing)
  8. Object to decision-making based only on automated profiling

The CCPA, on the other hand, grants California consumers five rights, which include the right to:

  1. Know
  2. Access
  3. Object (to sale of their data)
  4. Erasure
  5. Service without discrimination

The two laws differ slightly in the meaning of “right to object.” Whereas the GDPR affords its subjects the rights to object to direct marketing and to restrict the processing of their personal data, the CCPA provides a related, yet different right: the right to object to the sale of their data.

Furthermore, the CCPA specifies the “right to nondiscrimination,” meaning consumers who choose to exercise their CCPA rights are entitled to equal prices, products and services as any other customer.

Exemptions

Finally, let’s review exemptions to the GDPR and the CCPA.

Although the GDPR is a law passed by the EU parliament, the GDPR does not apply in its entirety to all EU member states. Article 23 of the GDPR allows member states to reasonably modify and/or restrict certain data rights when it comes to matters of national significance, for example:

  • Criminal investigations
  • Defense
  • National and public security
  • Economic and financial interests of the EU or the state

A list of GDPR exemptions available in the U.K., for instance, was recently published by the U.K. Information Commissioner’s Office.

Given that the CCPA is a law passed by a single U.S. state, it handles exemptions in a more direct manner: through the text of the law itself and through amendments. CCPA exemptions mostly pertain to personal data in business sectors that already have laws in place for regulating how data is processed. Examples include:

  • Consumer reports covered by the Fair Credit Reporting Act
  • Insurance-related data covered by the Gramm–Leach–Bliley Act and the California Financial Information Privacy Act
  • Health data covered by the Health Insurance Portability and Accountability Act (HIPAA)

Some CCPA exemptions are currently meant to be in effect only until January 1, 2021, giving lawmakers a year to pass supplementary data privacy laws that pertain to the following:

  • Job applicants
  • Employees
  • Contractors
  • Business-to-business transactions

What happens when those laws pass (or fail to pass) remains to be seen.

In addition to these exemptions, note that the CCPA applies to only a subset of companies that collect the personal data of California residents, as illustrated in the infographic. Furthermore, the CCPA does not apply to nonprofits. The GDPR casts a much wider net, with no revenue or volume thresholds.

Summary

GDPR-fatigued compliance officers may be dismayed by the new challenge of CCPA compliance. But, strategically speaking, those who’ve already developed systems and processes to satisfy the GDPR are in a good position due to overlap with the CCPA. Focusing on the key differences between these two regulatory behemoths can help ensure total compliance.

 


*More specifically, the GDPR applies to all entities that process the personal data of any resident of the European Union member states plus Iceland, Liechtenstein, Norway and Switzerland.


Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

5 Steps to Improve Board Monitoring of Compliance

Next Post

It’s Time to Reconsider the Term “Whistleblower”

Felix Sebastian

Felix Sebastian

Felix Sebastian is the Managing Editor at Termly, where he helps business owners generate privacy policies and other important legal documents, implement best business practices and comply with transnational privacy laws. He specializes in writing and curating compliance guides and law overviews for small business owners.

Related Posts

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
businesswoman in black blowing a whistle and pointing at the camera

It's Time to Reconsider the Term "Whistleblower"

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights