CCPA vs GDPR Data Subject Rights: Complete Comparison Matrix for Global Privacy Programs
CCPA and GDPR data subject rights differ significantly in scope, implementation requirements, and business obligations despite surface-level similarities. This detailed comparison matrix provides actionable guidance for privacy teams managing global compliance programs with specific attention to verification, response timelines, and exemption handling.
How do CCPA and GDPR data subject rights differ in fundamental scope?
CCPA provides four primary consumer rights (know, delete, opt-out, non-discrimination) while GDPR establishes eight comprehensive data subject rights with broader territorial and personal scope. CCPA applies to California residents' personal information regardless of processing location, whereas GDPR covers all EU data subjects with global territorial effect based on data controller establishment or targeting.
Scope Differences:
- CCPA/CPRA covers "consumers" defined as California residents, while GDPR protects "data subjects" including all EU residents and citizens
- CCPA focuses on "personal information" with commercial context emphasis, GDPR defines "personal data" more broadly including any information relating to identified individuals
- CCPA applies to businesses meeting revenue/data volume thresholds, GDPR applies to all data controllers regardless of size
What are the specific implementation differences for access rights?
Access rights implementation varies significantly between CCPA's "right to know" and GDPR's "right of access" in terms of information scope, format requirements, and delivery mechanisms.
CCPA Right to Know Requirements:
- Categories of personal information collected, sold, or disclosed
- Categories of sources from which personal information was collected
- Commercial or business purposes for collecting personal information
- Categories of third parties with whom personal information is shared
- Specific pieces of personal information collected (upon separate request)
GDPR Right of Access Requirements:
- Confirmation of processing and purposes of processing
- Categories of personal data and recipients of data
- Retention period or determination criteria
- Rights to rectification, erasure, or restriction
- Right to lodge supervisory authority complaints
- Source of data when not collected directly
- Existence of automated decision-making including profiling
Response Format Differences:
- CCPA permits delivery via mail or electronically, with portable format only required for specific pieces
- GDPR mandates structured, commonly used, machine-readable format when technically feasible
- CCPA allows authentication through existing customer accounts
- GDPR requires reasonable measures to verify data subject identity without requesting excessive information
How do deletion rights compare between CCPA and GDPR?
Deletion rights show substantial differences in scope, exceptions, and implementation requirements between CCPA's "right to delete" and GDPR's "right to erasure."
CCPA Right to Delete Scope: CCPA deletion applies to personal information collected from consumers, with businesses required to direct service providers to delete information unless legal or operational exceptions apply. The right covers consumer-provided information and information collected through consumer interaction.
GDPR Right to Erasure Scope: GDPR erasure encompasses broader circumstances including lawful basis withdrawal, objection to processing, unlawful processing, legal compliance requirements, and information society services to children.
Exception Handling Differences:
CCPA Deletion Exceptions:
- Complete transaction for which information was collected
- Detect security incidents and protect against fraudulent activity
- Debug products to identify and repair functionality errors
- Exercise free speech or ensure another consumer's free speech rights
- Comply with California Electronic Communications Privacy Act
- Engage in research in the public interest with consumer consent
- Internal uses reasonably aligned with consumer expectations
GDPR Erasure Exceptions:
- Exercise of freedom of expression and information rights
- Compliance with legal obligations or public interest tasks
- Public health reasons in the public interest
- Archiving, research, or statistical purposes with appropriate safeguards
- Establishment, exercise, or defence of legal claims
What verification requirements apply to data subject requests?
Verification procedures differ significantly between jurisdictions, affecting operational implementation and user experience design.
CCPA Verification Standards:
- Requests for categories of information: verify identity to reasonable degree of certainty
- Requests for specific pieces: verify identity to reasonably high degree of certainty
- Authorised agents: verify agent authority through power of attorney or signed permission
- Account holders: verify through existing authentication procedures
GDPR Verification Approach:
- "Reasonable measures" standard without specific certainty degrees
- Verification should not request excessive information
- Consider processing purposes and potential adverse effects
- Digital services may use additional authentication for electronic delivery
Operational Implementation:
- CCPA verification often requires matching two data points (email + phone, address + date of birth)
- GDPR verification emphasises proportionality and data minimisation
- CCPA permits charging fees for excessive or unfounded requests
- GDPR allows reasonable fees only for manifestly unfounded or excessive requests
How do response timelines and extension criteria compare?
Response timeframes and extension procedures show important differences affecting operational planning and consumer communication.
CCPA Response Timeline:
- Initial response: 45 days from verifiable request receipt
- Extension: Additional 45 days with consumer notification of extension and reason
- Total maximum: 90 days
- Extension criteria: "reasonably necessary" considering request complexity and volume
GDPR Response Timeline:
- Initial response: One month from request receipt
- Extension: Additional two months with data subject notification
- Total maximum: Three months
- Extension criteria: request complexity and number of requests
Communication Requirements:
- CCPA requires extension notification including extension reason
- GDPR mandates extension notification within one month of original request
- Both require refusal explanations when requests cannot be fulfilled
- GDPR includes supervisory authority complaint rights in refusal communications
What opt-out and portability rights exist under each framework?
Opt-out mechanisms and data portability show fundamental philosophical differences between consumer control approaches.
CCPA Opt-Out Rights:
- Right to opt-out of sale of personal information
- Right to opt-out of sharing for cross-context behavioural advertising (CPRA)
- Right to limit use of sensitive personal information (CPRA)
- "Do Not Sell My Personal Information" link requirements
GDPR Portability and Objection Rights:
- Right to data portability for consent-based and contract-based processing
- Right to object to legitimate interest processing
- Right to object to direct marketing processing
- Absolute right to object to profiling for direct marketing
Implementation Differences:
- CCPA focuses on commercial data monetisation control
- GDPR emphasises individual autonomy and data mobility
- CCPA opt-out applies to defined "sale" transactions
- GDPR objection requires balancing test for legitimate interests
Integrating both frameworks requires comprehensive privacy program design addressing the most restrictive requirements from each jurisdiction. Organisations often implement GDPR-level protections globally while adding CCPA-specific mechanisms like sale opt-out for California residents.
Global Privacy Program Integration:
- Implement unified request intake systems handling both CCPA and GDPR requirements
- Establish verification procedures meeting the higher CCPA standard
- Design response templates addressing jurisdiction-specific information requirements
- Create exception handling workflows accommodating different legal bases
This comprehensive approach ensures compliance with both frameworks while minimising operational complexity and maintaining consistent user experience across jurisdictions.
Frequently Asked Questions
What does this article cover?
Who should read this privacy article?
How can I apply these privacy insights?
Explore this topic on our compliance platform
Our platform covers 692 compliance frameworks with 819,000+ cross-framework control mappings. Start free, no credit card required.
Try the Platform Free →