No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Where the CCPA and GDPR Overlap and Diverge

An Illustrated Comparison of the Regulations

by Felix Sebastian
November 14, 2019
in Data Privacy
businessman touching virtual data shield

Before the CCPA becomes law on January 1, 2020, compliance officers worldwide (not just in California or the U.S.) need to be sure their companies are compliant. Are steps taken toward GDPR compliance sufficient? Termly’s Felix Sebastian explores the differences between the regulations.

Since the General Data Protection Regulation (GDPR) took force, businesses have collectively spent billions of dollars and “hundreds of years of human time” on compliance efforts. These numbers look excessive at first glance, but with the GDPR supervisory authorities handing out multimillion-dollar fines to Google and other corporate giants this year, investing in prevention measures is cheaper than coughing up 4 percent of revenue.

Data protection officers and consumers alike are only just adjusting to this new era of data privacy laws, but another major regulation — the California Consumer Privacy Act (CCPA) — is awaiting its turn to go live on January 1, 2020.

Knowing how the CCPA and the GDPR differ (and are similar) is crucial to effectively prepare for upcoming CCPA compliance challenges. Here’s an infographic to help you get started on this research.

differences between CCPA and GDPR
Infographic courtesy of Termly

While the infographic compares the fundamentals of the GDPR and the CCPA, here are a few more similarities and differences worth noting:

Extraterritoriality — Who’s Covered?

Both the GDPR and the CCPA are extraterritorial in their scope. This means that while these two laws are based in the European Union (EU) and the U.S. state of California (CA), the laws still apply to businesses worldwide that target EU* and California residents, respectively.

Given the transnational nature of data and businesses in this internet age, extraterritoriality is a standard component in new privacy laws around the world, such as those in Thailand and Brazil.

Personal Data — What’s “Personal?”

At the core of both the GDPR and the CCPA lies the protection of personal data. However, the two laws differ in how they define “personal;” these distinctions in phrasing, though minor, have practical implications for businesses.

The GDPR uses the term “personal data” and defines it as “information that relates to an identified or identifiable individual.”

In contrast, the CCPA uses the term “personal information” and defines it as “information that identifies, relates to, describes, is capable of being associated with or could reasonably be linked, directly or indirectly, with a particular consumer or household.”

The CCPA’s use of “reasonably” in its definition provides more room for interpretation. In practice, this means that, for example, hashed data might not be deemed “personal” under the CCPA. We’ll have to wait and see how the interpretations of the enforcement agencies, businesses and consumers play out in the months following the CCPA taking effect.

Rights — What’s Provided?

Both the GDPR and the CCPA entitle their subjects to know what personal information is collected from them (and whether and with whom it’s shared), to access this information and to request that it be erased.

Specifically, the GDPR gives EU* consumers eight rights over their personal data. Those include the right to:

  1. Know
  2. Access
  3. Rectify
  4. Erasure
  5. Restrict (processing)
  6. Data portability
  7. Object (to direct marketing)
  8. Object to decision-making based only on automated profiling

The CCPA, on the other hand, grants California consumers five rights, which include the right to:

  1. Know
  2. Access
  3. Object (to sale of their data)
  4. Erasure
  5. Service without discrimination

The two laws differ slightly in the meaning of “right to object.” Whereas the GDPR affords its subjects the rights to object to direct marketing and to restrict the processing of their personal data, the CCPA provides a related, yet different right: the right to object to the sale of their data.

Furthermore, the CCPA specifies the “right to nondiscrimination,” meaning consumers who choose to exercise their CCPA rights are entitled to equal prices, products and services as any other customer.

Exemptions

Finally, let’s review exemptions to the GDPR and the CCPA.

Although the GDPR is a law passed by the EU parliament, the GDPR does not apply in its entirety to all EU member states. Article 23 of the GDPR allows member states to reasonably modify and/or restrict certain data rights when it comes to matters of national significance, for example:

  • Criminal investigations
  • Defense
  • National and public security
  • Economic and financial interests of the EU or the state

A list of GDPR exemptions available in the U.K., for instance, was recently published by the U.K. Information Commissioner’s Office.

Given that the CCPA is a law passed by a single U.S. state, it handles exemptions in a more direct manner: through the text of the law itself and through amendments. CCPA exemptions mostly pertain to personal data in business sectors that already have laws in place for regulating how data is processed. Examples include:

  • Consumer reports covered by the Fair Credit Reporting Act
  • Insurance-related data covered by the Gramm–Leach–Bliley Act and the California Financial Information Privacy Act
  • Health data covered by the Health Insurance Portability and Accountability Act (HIPAA)

Some CCPA exemptions are currently meant to be in effect only until January 1, 2021, giving lawmakers a year to pass supplementary data privacy laws that pertain to the following:

  • Job applicants
  • Employees
  • Contractors
  • Business-to-business transactions

What happens when those laws pass (or fail to pass) remains to be seen.

In addition to these exemptions, note that the CCPA applies to only a subset of companies that collect the personal data of California residents, as illustrated in the infographic. Furthermore, the CCPA does not apply to nonprofits. The GDPR casts a much wider net, with no revenue or volume thresholds.

Summary

GDPR-fatigued compliance officers may be dismayed by the new challenge of CCPA compliance. But, strategically speaking, those who’ve already developed systems and processes to satisfy the GDPR are in a good position due to overlap with the CCPA. Focusing on the key differences between these two regulatory behemoths can help ensure total compliance.

 


*More specifically, the GDPR applies to all entities that process the personal data of any resident of the European Union member states plus Iceland, Liechtenstein, Norway and Switzerland.


Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

5 Steps to Improve Board Monitoring of Compliance

Next Post

It’s Time to Reconsider the Term “Whistleblower”

Felix Sebastian

Felix Sebastian

Felix Sebastian is the Managing Editor at Termly, where he helps business owners generate privacy policies and other important legal documents, implement best business practices and comply with transnational privacy laws. He specializes in writing and curating compliance guides and law overviews for small business owners.

Related Posts

gdpr

UK Resurrects Data Protection Reforms, EU Court Rules on GDPR in Civil Cases

by Jonathan Armstrong and André Bywater
March 15, 2023

Recent courtroom and legislative action in Europe will likely have ripple effects around the world for companies subject to regulations...

eu flag

Preparing Your Company for the Latest GDPR Data Transfer Developments & Upcoming Deadlines

by Kevin L. Coy
November 30, 2022

An EU court decision and legislative moves in the U.S. and UK make compliance with privacy regulations increasingly difficult. Arnall...

minidata_b

Honey, I Shrunk the Data: How to Keep Customer Info on a Need-to-Know Basis

by Parker Poe
November 30, 2022

It may be tempting to hoard the data you have gathered on your customers, but an increasing number of regulations...

uk ico data access

UK’s Data Protection Regulator Signals Crackdown on Access Request Violations

by Jonathan Armstrong and André Bywater
October 5, 2022

Data privacy laws in the EU and UK established the right of individuals to find out what personal information organizations...

Next Post
businesswoman in black blowing a whistle and pointing at the camera

It's Time to Reconsider the Term "Whistleblower"

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Code of Conduct Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT