Privacy Laws in the US and EU: GDPR, CCPA & CPRA Guide
If the darknet discussion is about exposure, privacy law is about control. After a breach, your leverage comes from these statutes. This primer compares the EU's GDPR with California's CCPA as amended by CPRA - the two regimes most readers in the US/EU will encounter - with notes on the broader US patchwork.
1. Who Is Covered?
| GDPR (EU/EEA & UK GDPR) | CCPA/CPRA (California) | |
|---|---|---|
| Territory | Anyone processing data of people in the EU, regardless of where the company sits | For-profit entities doing business in California meeting thresholds (e.g., 100k+ CA residents' data) |
| Data | Any personal data (including pseudonymous, IP, cookies) | Personal information linked to households; sensitive PI gets extra limits (CPRA) |
| Actors | Controller vs processor - both liable | Business / service provider / contractor / third party |
By 2026, 15+ US states have separate privacy acts (Colorado, Connecticut, Virginia, etc.) modeled on CCPA. Expect similar rights but different thresholds - check your state's AG.
2. Rights Compared
| Right | GDPR | CCPA/CPRA |
|---|---|---|
| Know / access | Art. 15 - copy of data + purposes, recipients, retention | Right to know - twice per 12 months, free |
| Delete | Art. 17 - "right to be forgotten, with exceptions | Right to delete, with exceptions (e.g., security, legal) |
| Correct | Art. 16 - rectify inaccurate data | Right to correct (CPRA added) |
| Opt out of sale/share | Via consent / legitimate interest limits; Art. 21 objection | Do Not Sell/Share + Limit Use of Sensitive PI (CPRA) |
| Non-discrimination | Implied via fairness | Explicit - no retaliation for exercising rights |
Both require 45-day response (GDPR: one month, extendable by two; CCPA: 45 days + 45). Both require verification of requestor - but not collection of extra data.
3. Breach Notification
- GDPR Art. 33/34: Controller must notify its supervisory authority within 72 hours of becoming aware, unless unlikely to risk rights. If high risk, notify affected individuals without undue delay.
- CCPA/CPRA + state breach laws: No single federal 72h rule; each state's breach law requires "expedient or 30-"60 day notice. CPRA beefs up risk assessment and retention limits, but notification timelines still flow from state breach statutes (e.g., Cal. Civ. Code §1798.82).
4. Fines & Enforcement
- GDPR: Up to ‚¬20M or 4% global annual turnover (whichever higher). Enforced by national DPAs + EDPB. See EDPB and ICO.
- CCPA/CPRA: $2,500 per unintentional, $7,500 per intentional violation; enforced by AG and new CPPA agency. Private right of action limited mainly to data breaches from failure to implement reasonable security.
US federal law is sectoral - HIPAA, GLBA, COPPA - not omnibus. The FTC acts via unfair-practice authority, not a general privacy statute (as of 2026).
5. How to Exercise Rights (Templates)
Step 1 - Find the controller/business
Look for "Privacy Policy -> Contact / DPO or "Do Not Sell My Info. For EU, address the controller; for CCPA, the business.
Step 2 - Send a verifiable request
Email template (short):
"Subject: GDPR Art. 15 / CCPA Request to Know & Delete. Please confirm what personal data you hold about [email], purposes, recipients, retention, and delete it unless an exception applies. Verify me via [method]. Please respond within statutory deadline."
Step 3 - Escalate if needed
EU: lodge a complaint with your DPA (list at EDPB members). US/CA: contact oag.ca.gov/privacy/ccpa or your state AG.
Combine with technical steps from What to Do After a Breach and detection from dark web monitoring.