See where CDP is headed with AI — Agentic World 2026, Oct 5–7, Miami →
Glossary

Data Privacy Regulations: GDPR, CCPA & Global Laws

Data privacy regulations give individuals legal rights over their personal data. How GDPR, CCPA, and PIPEDA work, who must comply, and what violations cost.

CDP.com Staff CDP.com Staff 7 min read

Data privacy regulations are legal frameworks that protect the personal data of citizens or residents within specific jurisdictions, granting individuals rights over how businesses collect, store, and use their information. These data privacy regulations can exist at the multi-national, national, state, and local levels.

Typically, data privacy regulations apply to commercial organizations and can dictate how they collect, store, and process personally identifiable information (PII). They can affect businesses operating in a location even if the business is located elsewhere.

The types of personal data that are protected, as well as how long data can be stored and what purposes it can be used for, can vary greatly for each regulation. Proper data governance is essential for compliance. Non-compliance can lead to different outcomes per guideline but can include warnings, bans on an organization’s ability to process personal data, and fines of up to millions or even billions of dollars.

More than 100 such laws now exist worldwide. This page explains how the major regulations work; for the complete reference of data privacy laws by country and U.S. state, see our dedicated guide.

Examples of Data Privacy Regulations

What is The General Data Protection Regulation (GDPR)?

GDPR is a data privacy law that protects the privacy of individuals in the European Union. It includes a list of privacy rights of individuals in the EU and also includes data protection principles that organizations processing personal data must uphold. Examples of protected data under GDPR include names, email addresses, physical addresses, ethnicity, gender, and web cookies.

GDPR principles stipulate several requirements. For example, they require that data is processed following all laws and in a way that’s fair and transparent to the individual. They also require that the purpose of processing the data be specified when it’s collected and that organizations only collect as much data as needed for that purpose. The individual’s data must be kept up-to-date for as long as the business stores it, and the data can’t be kept any longer than needed for the purpose it was collected for.

GDPR also requires that safety measures — including consent management mechanisms — are taken when processing data to preserve confidentiality and security, and restricts who within an organization can have access to personal data and who will be responsible for demonstrating compliance.

What is The California Consumer Privacy Act (CCPA)?

CCPA protects California residents, even if they’re temporarily not in the state. It gives them rights such as knowing the information a business collects and how the organization will use and share the data. It also gives them the right to delete personal data that a business collects, opt out of their information being sold, and the right to non-discrimination if they decide to exercise any of their rights under CCPA.

CCPA protects personally identifiable information (PII) as well as information that can be linked to a household such as names, emails, social security numbers, purchase history, online browsing history, geolocation data, and fingerprints.

Unlike GDPR, CCPA has more specific requirements for the businesses it applies to, such as annual gross revenue, the number of California residents it buys, receives, or sells data from, or how much of the organization’s revenue is from selling residents’ personal data.

What is The Personal Information Protection and Electronic Documents Act (PIPEDA)?

PIPEDA is one of Canada’s national privacy laws, though the country also has a separate Privacy Act. It applies to all private-sector organizations operating in Canada that conduct commercial activity and handle personal information.

The act generally protects information such as names, DNA, ages, marital status, race, national or ethnic origin, medical history, education history, employment history, financial information, and identifying numbers like a social insurance number. To comply with PIPEDA, businesses must adhere to 10 principles similar to those under GDPR.

How Major Data Privacy Regulations Compare

The strictest data privacy regulations by penalty are the EU’s GDPR (up to €20 million or 4% of global annual revenue) and China’s PIPL (up to ¥50 million or 5% of annual revenue). The table below compares the major regulations in force as of 2026:

RegulationJurisdictionEffectiveWho It ProtectsMaximum Penalty
GDPR (General Data Protection Regulation)European Union / EEAMay 25, 2018Individuals in the EU/EEA€20 million or 4% of global annual revenue, whichever is higher
CCPA/CPRA (California Consumer Privacy Act, as amended)California, USAJan 1, 2020 (CPRA amendments Jan 1, 2023)California residents$2,500 per violation; $7,500 per intentional violation (assessed per consumer — fines compound at scale)
PIPEDA (Personal Information Protection and Electronic Documents Act)Canada (federal, private sector)Fully in force Jan 1, 2004Canadian consumersCAD $100,000 per offence (breach-reporting and obstruction offences only)
PIPL (Personal Information Protection Law)ChinaNov 1, 2021Individuals in China¥50 million or 5% of annual revenue
LGPD (Lei Geral de Proteção de Dados)BrazilSep 18, 2020Individuals in Brazil2% of Brazil revenue, capped at R$50 million per violation
DPDP Act (Digital Personal Data Protection Act)IndiaEnacted Aug 2023; rules phasing in through 2027Individuals in India₹250 crore (approx. US$30 million)

Penalties are only part of the picture. These regulations also differ in the individual rights they grant — access, deletion, portability, opt-out of sale — and in cross-border transfer rules. PIPL, for example, requires security assessments before transferring personal information outside China, a data-residency constraint GDPR and CCPA do not impose.

What Data Privacy Regulations Mean for Customer Data Strategy

For marketing and data teams, privacy regulations translate into three operational requirements: capturing consent, honoring it in every channel, and deleting customer data on request.

  • Consent must be enforced everywhere, not just recorded. Email, advertising, and analytics systems all need to respect the customer’s current consent state, not the state at the time of collection.
  • Deletion requests must propagate. When a customer exercises their right to erasure, every system holding a copy of their record must execute it — practical only when customer data is unified rather than scattered across tools.
  • Regulations reward centralized first-party data. A governed, single view of the customer — for example in a customer data platform (CDP) — makes rights fulfillment and audit trails tractable.

FAQ

What happens if a company violates data privacy regulations?

Violations can result in fines of up to €20 million or 4% of annual global revenue under GDPR — whichever is higher. Beyond fines, companies may face enforcement actions like bans on processing personal data, mandatory audits, and legal action from affected individuals. Reputational damage and loss of customer trust can also have long-term business impacts.

Do data privacy regulations apply to companies outside their jurisdiction?

Yes — many privacy regulations have extraterritorial reach and apply to companies processing data of residents in that jurisdiction, regardless of where the company is located. GDPR applies to any organization processing the data of individuals in the EU, and CCPA applies to businesses handling California residents’ data. This means companies worldwide must comply if they serve customers in these regions.

How often do data privacy regulations change?

Data privacy regulations evolve continuously — new laws are introduced every year at national, state, and local levels, and existing regulations are amended to address gaps. Companies should monitor regulatory developments quarterly and work with legal counsel to maintain compliance as requirements change. A customer data platform with consent enforcement and deletion propagation can help operationalize specific obligations: honoring opt-outs across channels and executing deletion requests against unified profiles. Enterprise CDPs including Salesforce Data Cloud, Adobe Real-Time CDP, and Treasure AI (formerly Treasure Data) natively support consent enforcement and deletion-request propagation across unified profiles. Compliance itself, however, remains a legal and governance function first.

  • Data Masking — Technique for protecting PII to meet regulatory requirements
  • Cookieless Tracking — Privacy-compliant alternative emerging from stricter regulations
  • Data Clean Room — Enables data collaboration without exposing regulated personal data
  • Consent Management — Operationalizes regulatory consent requirements across channels
CDP.com Staff
Written by

The CDP.com staff has collaborated to deliver the latest information and insights on the customer data platform industry.