Data Privacy Compliance: GDPR, CCPA, and the Growing Patchwork of State Laws
March 3, 2026
The New Reality of Data Privacy
A decade ago, privacy law was largely confined to specific regulated industries — healthcare (HIPAA), financial services (GLBA), and children's data (COPPA). Today, a broad and expanding patchwork of federal and state privacy laws applies to almost every business that collects personal information about consumers. The failure to comply can result in regulatory enforcement, private lawsuits, and — perhaps most consequentially — the kind of public trust damage that is difficult to recover from.
For businesses, particularly those with online presences or digital products, understanding the data privacy landscape is no longer optional. This guide walks through the major frameworks and what they require.
The General Data Protection Regulation (GDPR)
The EU's General Data Protection Regulation, effective since May 2018, is the most comprehensive privacy law currently in force and applies extraterritorially to any organization that processes the personal data of EU residents, regardless of where the organization is located. For U.S. businesses with EU customers, website visitors, or employees, GDPR compliance is not optional.
Key GDPR Requirements
- Lawful basis for processing: Every collection and use of personal data must have a lawful basis — consent, contract performance, legal obligation, vital interests, public task, or legitimate interests. Consent (when relied upon) must be freely given, specific, informed, and unambiguous.
- Data subject rights: EU residents have extensive rights including access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing. Organizations must have processes to respond to these requests within specified timeframes.
- Privacy notices: Organizations must provide clear, accessible information about their data processing at the point of collection.
- Data protection by design and default: Privacy considerations must be built into products and processes from the beginning, not bolted on later.
- Data breach notification: Data breaches must be reported to supervisory authorities within 72 hours and, in many cases, to affected individuals.
- Data processing agreements: When personal data is shared with processors (service providers), a Data Processing Agreement (DPA) is required.
GDPR penalties are substantial: up to €20 million or 4% of global annual revenue for the most serious violations, whichever is higher.
The California Consumer Privacy Act and CPRA
The California Consumer Privacy Act (CCPA), amended and expanded by the California Privacy Rights Act (CPRA), is the most comprehensive U.S. privacy law and has served as the model for privacy legislation in many other states. It applies to businesses that: (1) have annual gross revenues over $25 million; (2) annually buy, sell, receive, or share the personal information of 100,000 or more consumers or households; or (3) derive 50% or more of annual revenues from selling or sharing consumers' personal information.
Key CCPA/CPRA Rights
- Right to know: Consumers can request disclosure of the personal information a business has collected about them, the categories of sources, the business purpose, and the categories of third parties with whom it's shared.
- Right to delete: Consumers can request deletion of their personal information, subject to specified exceptions.
- Right to correct: Consumers can request correction of inaccurate personal information (added by CPRA).
- Right to opt out of sale/sharing: Consumers can direct businesses not to sell or share their personal information (including for cross-context behavioral advertising).
- Right to limit use of sensitive personal information: Consumers can limit the use of sensitive personal information (SSNs, financial account data, precise geolocation, racial/ethnic origin, health information, etc.) to specified permitted purposes.
The State Privacy Law Patchwork (2024-2026)
Following California's lead, a significant number of states have enacted comprehensive privacy laws, and more are in progress. States with comprehensive privacy laws in effect or forthcoming include Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Texas, Oregon, Florida, and others. Each has its own scope, applicability thresholds, and specific requirements — creating significant compliance complexity for businesses operating nationally.
Common threads across most state privacy laws include: (1) consumer rights to access, delete, and correct personal information; (2) opt-out rights for the sale of personal information and for targeted advertising; (3) data protection assessment requirements for high-risk processing activities; and (4) data minimization principles. Key differences include the scope of entities covered, the rights granted, the enforcement mechanisms (private right of action vs. AG-only enforcement), and the specific obligations around sensitive data categories.
What Businesses Should Do Now
- Data mapping: Understand what personal data you collect, where it comes from, how it's used, where it's stored, and who has access to it. You can't protect what you can't see.
- Privacy policy: Ensure your privacy policy accurately describes your data practices and complies with applicable law. A privacy policy is a legal disclosure — not just a formality.
- Vendor management: Implement data processing agreements (or GDPR-equivalent DPAs) with vendors who process personal data on your behalf.
- Data subject rights process: Establish processes for receiving, verifying, and responding to consumer rights requests within required timeframes.
- Data breach response plan: Have a plan in place for detecting, containing, and reporting data breaches before one happens.
- Cookie consent: If you serve EU users, implement a compliant cookie consent mechanism for cookies that are not strictly necessary.