Privacy & Law - Primer

Privacy Laws in the US and EU: GDPR, CCPA & CPRA Guide

Scales of justice representing GDPR and CCPA privacy law comparison
EU GDPR is omnibus; US privacy is a patchwork led by California's CCPA/CPRA. Both give you deletion and access rights - but triggers and timelines differ.

If the darknet discussion is about exposure, privacy law is about control. After a breach, your leverage comes from these statutes. This primer compares the EU's GDPR with California's CCPA as amended by CPRA - the two regimes most readers in the US/EU will encounter - with notes on the broader US patchwork.

1. Who Is Covered?

GDPR (EU/EEA & UK GDPR)CCPA/CPRA (California)
TerritoryAnyone processing data of people in the EU, regardless of where the company sitsFor-profit entities doing business in California meeting thresholds (e.g., 100k+ CA residents' data)
DataAny personal data (including pseudonymous, IP, cookies)Personal information linked to households; sensitive PI gets extra limits (CPRA)
ActorsController vs processor - both liableBusiness / service provider / contractor / third party

By 2026, 15+ US states have separate privacy acts (Colorado, Connecticut, Virginia, etc.) modeled on CCPA. Expect similar rights but different thresholds - check your state's AG.

2. Rights Compared

RightGDPRCCPA/CPRA
Know / accessArt. 15 - copy of data + purposes, recipients, retentionRight to know - twice per 12 months, free
DeleteArt. 17 - "right to be forgotten, with exceptionsRight to delete, with exceptions (e.g., security, legal)
CorrectArt. 16 - rectify inaccurate dataRight to correct (CPRA added)
Opt out of sale/shareVia consent / legitimate interest limits; Art. 21 objectionDo Not Sell/Share + Limit Use of Sensitive PI (CPRA)
Non-discriminationImplied via fairnessExplicit - no retaliation for exercising rights

Both require 45-day response (GDPR: one month, extendable by two; CCPA: 45 days + 45). Both require verification of requestor - but not collection of extra data.

3. Breach Notification

  • GDPR Art. 33/34: Controller must notify its supervisory authority within 72 hours of becoming aware, unless unlikely to risk rights. If high risk, notify affected individuals without undue delay.
  • CCPA/CPRA + state breach laws: No single federal 72h rule; each state's breach law requires "expedient or 30-"60 day notice. CPRA beefs up risk assessment and retention limits, but notification timelines still flow from state breach statutes (e.g., Cal. Civ. Code §1798.82).
Practical tip: If a company says "we had a breach, ask for: (a) date they became aware, (b) whether they filed with a DPA/AG, (c) what they did to mitigate (forced resets). That maps directly to their GDPR/CCPA obligations.

4. Fines & Enforcement

  • GDPR: Up to ‚¬20M or 4% global annual turnover (whichever higher). Enforced by national DPAs + EDPB. See EDPB and ICO.
  • CCPA/CPRA: $2,500 per unintentional, $7,500 per intentional violation; enforced by AG and new CPPA agency. Private right of action limited mainly to data breaches from failure to implement reasonable security.

US federal law is sectoral - HIPAA, GLBA, COPPA - not omnibus. The FTC acts via unfair-practice authority, not a general privacy statute (as of 2026).

5. How to Exercise Rights (Templates)

Step 1 - Find the controller/business

Look for "Privacy Policy -> Contact / DPO or "Do Not Sell My Info. For EU, address the controller; for CCPA, the business.

Step 2 - Send a verifiable request

Email template (short):

"Subject: GDPR Art. 15 / CCPA Request to Know & Delete. Please confirm what personal data you hold about [email], purposes, recipients, retention, and delete it unless an exception applies. Verify me via [method]. Please respond within statutory deadline."

Step 3 - Escalate if needed

EU: lodge a complaint with your DPA (list at EDPB members). US/CA: contact oag.ca.gov/privacy/ccpa or your state AG.

Combine with technical steps from What to Do After a Breach and detection from dark web monitoring.

Not legal advice. Citations: Wikipedia: GDPR, gdpr.eu, oag.ca.gov. Last reviewed Aug 27, 2026.