• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
Montreal AI Ethics Institute

Montreal AI Ethics Institute

Democratizing AI ethics literacy

  • Articles
    • Public Policy
    • Privacy & Security
    • Human Rights
      • Ethics
      • JEDI (Justice, Equity, Diversity, Inclusion
    • Climate
    • Design
      • Emerging Technology
    • Application & Adoption
      • Health
      • Education
      • Government
        • Military
        • Public Works
      • Labour
    • Arts & Culture
      • Film & TV
      • Music
      • Pop Culture
      • Digital Art
  • Columns
    • AI Policy Corner
    • Recess
    • Tech Futures
  • The AI Ethics Brief
  • AI Literacy
    • Research Summaries
    • AI Ethics Living Dictionary
    • Learning Community
  • The State of AI Ethics Report
    • Volume 7 (November 2025)
    • Volume 6 (February 2022)
    • Volume 5 (July 2021)
    • Volume 4 (April 2021)
    • Volume 3 (Jan 2021)
    • Volume 2 (Oct 2020)
    • Volume 1 (June 2020)
  • About
    • Our Contributions Policy
    • Our Open Access Policy
    • Contact
    • Donate

Research summary: Comparing Privacy Law GDPR Vs CCPA

August 17, 2020

Summary contributed by Sundar Narayanan, Director at Nexdigm and ethics & compliance professional.

*Authors of full paper & link at the bottom


Mini-summary: The paper is a summary of key similarities and distinctions between GDPR and CCPA. The paper analyses these similarities and distinctions in areas including scope, definitions, legal, rights and enforcement areas. 

The scope is fairly inconsistent, definitions are fairly consistent, legal grounds are inconsistent, rights are fairly consistent in some cases and enforcement is inconsistent. These analyses are based on the regulations themselves.


Full summary:

The paper details out the key differences between the two regulations. The similarities and differences are classified in the following areas:

  1. Scope
  2. Definitions
  3. Legal Basis
  4. Rights
  5. Enforcement

Scope: The section covers personal scope, territorial scope and material scope. 

AspectDegree of similarityRemarks
Personal scopeFairly inconsistentBoth apply to natural persons. CCPA applies to only residents and only for profit entities unlike GDPR which applies to even non profit entities
Territorial scopeFairly inconsistentCCPA stresses on doing business in california, while GDPR is applicable for companies outside EU also to the extent they have access to data of data subjects from EU
Material scopeFairly consistentDefinitions of personal data and processing have similarities. CCPA has exclusions for medical info, info regarding clinical trials etc, unlike GDPR which does not have such differences

Definitions: The section covers the key definitions including personal data, pseudonymisation, controllers, processors etc

AspectDegree of similarityRemarks
Personal dataFairly consistentBoth have consistent definitions of personal info and do not apply to anonymised/ de identified data. CCPA does not apply to publicly available information, unlike GDPR. Similarly, GDPR prohibits processing of special categories of personal data, unlike CCPA, which does not have such definitions
PseudonymisationFairly consistentBoth have consistent definitions of Pseudonymisation. CCPA defines that reidentification is not required if information to link the same as personal information not maintained, unlike GDPR
Controllers & processorsFairly consistentBoth have consistent definitions including data processor/ service provider, binding / written contracts,right to deletion and misuse of personal info. GDPR imposes obligations of privacy impact assessment, appointing DPO and notification of breaches, which are not there clearly in CCPA 

Legal: This section deals with legal grounds for processing

AspectDegree of similarityRemarks
Legal groundsInconsistentGDPR limits data controllers from processing data when there is a legal ground (consent, contractual obligation etc) for it, unlike CCPA, which requires consent when there is a financial incentive out of the personal info 

Rights: This section covers right to erasure, right to be informed right to object and right of access

AspectDegree of similarityRemarks
Right to erasureFairly consistentBoth have the scope that extends beyond data collectors to third parties to whom data is sold or passed on, expresses that the right is free of cost and mandates mechanisms for compliance. However both regulations have differences in lead time to respond to such requests. 
Right to be informedFairly consistentBoth mandate that data controllers cannot process data for purposes for which it is collected. 
Right to objectFairly inconsistentRight to opt out in CCPA is an absolute right and cannot be withdrawn. Further in CCPA the right is limited to selling or disclosing of the data and not for processing unlike GDPR.
Right of accessFairly inconsistentBoth express that the businesses must have in place mechanisms to enable such requests. CCPA has limitation of time of data collected (12 months), unlike GDPR
Right not to be discriminatedInconsistentCCPA provides that consumers must not be discriminated against for exercising their rights including being denied goods or services, charged differential prices or providing different quality of service. Such provision does not exist in GDPR
Right to data portabilityFairly consistentBoth reflect that the data shall be portable in readily usable format free of charge

Enforcement: This section covers monetary penalties and civil remedies for individuals

AspectDegree of similarityRemarks
Monetary penaltyInconsistentThe penalties are varied with CCPA defining it at a violation level, while GDPR expresses it as a proportion of overall turnover.
Civil remediesInconsistentCCPA allows the remedy only when non-encrypted or nonredacted personal information is subject to an unauthorized access, unlike GDPR which can get triggered for any violation. 

Original paper by:

  • DataGuidance: Alice Marini, Alexis Kateifides, Joel Bates
  • Future of Privacy Forum: Gabriela Zanfir-Fortuna, Michelle Bae, Stacey Gray, Gargi Sen
  • Link to paper: https://arxiv.org/ftp/arxiv/papers/2006/2006.16179.pdf
Want quick summaries of the latest research & reporting in AI ethics delivered to your inbox? Subscribe to the AI Ethics Brief. We publish bi-weekly.

Primary Sidebar

🔍 SEARCH

Spotlight

Close-up of a cat sleeping on a computer keyboard

Tech Futures: The threat of AI-generated code to the world’s digital infrastructure

The undying sun hangs in the sky, as people gather around signal towers, working through their digital devices.

Dreams and Realities in Modi’s AI Impact Summit

Illustration of a coral reef ecosystem

Tech Futures: Diversity of Thought and Experience: The UN’s Scientific Panel on AI

This image shows a large white, traditional, old building. The top half of the building represents the humanities (which is symbolised by the embedded text from classic literature which is faintly shown ontop the building). The bottom section of the building is embossed with mathematical formulas to represent the sciences. The middle layer of the image is heavily pixelated. On the steps at the front of the building there is a group of scholars, wearing formal suits and tie attire, who are standing around at the enternace talking and some of them are sitting on the steps. There are two stone, statute-like hands that are stretching the building apart from the left side. In the forefront of the image, there are 8 students - which can only be seen from the back. Their graduation gowns have bright blue hoods and they all look as though they are walking towards the old building which is in the background at a distance. There are a mix of students in the foreground.

Tech Futures: Co-opting Research and Education

Agentic AI systems and algorithmic accountability: a new era of e-commerce

related posts

  • What lies behind AGI: ethical concerns related to LLMs

    What lies behind AGI: ethical concerns related to LLMs

  • Bias in Automated Speaker Recognition

    Bias in Automated Speaker Recognition

  • The Canada Protocol: AI checklist for Mental Health & Suicide Prevention

    The Canada Protocol: AI checklist for Mental Health & Suicide Prevention

  • Towards an Understanding of Developers' Perceptions of Transparency in Software Development: A Preli...

    Towards an Understanding of Developers' Perceptions of Transparency in Software Development: A Preli...

  • Emerging trends: Unfair, biased, addictive, dangerous, deadly, and insanely profitable

    Emerging trends: Unfair, biased, addictive, dangerous, deadly, and insanely profitable

  • Acceptable Risks in Europe’s Proposed AI Act: Reasonableness and Other Principles for Deciding How M...

    Acceptable Risks in Europe’s Proposed AI Act: Reasonableness and Other Principles for Deciding How M...

  • How Naysan Saran disrupted water quality detection in one hackathon

    How Naysan Saran disrupted water quality detection in one hackathon

  • Beyond Dependency: The Hidden Risk of Social Comparison in Chatbot Companionship

    Beyond Dependency: The Hidden Risk of Social Comparison in Chatbot Companionship

  • The Two Faces of AI in Green Mobile Computing: A Literature Review

    The Two Faces of AI in Green Mobile Computing: A Literature Review

  • The Ethics of Artificial Intelligence through the Lens of Ubuntu

    The Ethics of Artificial Intelligence through the Lens of Ubuntu

Partners

  •  
    U.S. Artificial Intelligence Safety Institute Consortium (AISIC) at NIST

  • Partnership on AI

  • The LF AI & Data Foundation

  • The AI Alliance

Footer


Articles

Columns

AI Literacy

The State of AI Ethics Report


 

About Us


Founded in 2018, the Montreal AI Ethics Institute (MAIEI) is an international non-profit organization equipping citizens concerned about artificial intelligence and its impact on society to take action.

Contact

Donate


  • © 2025 MONTREAL AI ETHICS INSTITUTE.
  • This work is licensed under a Creative Commons Attribution 4.0 International License.
  • Learn more about our open access policy here.
  • Creative Commons License

    Save hours of work and stay on top of Responsible AI research and reporting with our bi-weekly email newsletter.