Personal data compared: GDPR, CCPA/CPRA and PIPL
How do GDPR, CCPA and PIPL differ?
The three main personal data regimes cover the same records but start from different premises. The GDPR asks for a legal basis before processing. California gives the consumer rights after the fact. PIPL asks for separate consent for named categories.
Rows read against the registers 2026-08-26.
European Union
- GDPR — Regulation (EU) 2016/679, 32016R0679: Requires a legal basis per purpose, information to the person, and rights of access, correction and erasure.
- ePrivacy Directive — Directive 2002/58/EC, 32002L0058: Covers terminal equipment: cookies and similar reading of a device need consent unless strictly necessary.
Open the European Union register
United States
- California Consumer Privacy Act, as amended by the CPRA, Cal. Civ. Code § 1798.100 et seq.: Applies above stated thresholds. Consumers can know, delete, correct and opt out of sale or sharing.
- FTC Act Section 5, unfair or deceptive practices in AI and data, 15 U.S.C. § 45: Data claims in a privacy notice are enforceable as representations under Section 5.
Open the United States register
China
- Personal Information Protection Law of the People's Republic of China, PIPL, adopted by the NPCSC on 20 August 2021: Requires a lawful ground, separate consent for sensitive categories and a named person responsible.
What they ask for in common
- All three give the individual a right to know what is held about them.
- All three require the purpose to be written down before the data is used.
- All three make the notice binding: what you write is what you are held to.
Where they differ
- The GDPR needs a basis before processing. The CCPA works through rights and opt-outs after collection.
- PIPL asks for separate consent per sensitive purpose, which the GDPR handles through Article 9 conditions.
- The CCPA applies above revenue and volume thresholds. The GDPR and PIPL have no such general threshold.
What companies usually do first
- List the purposes first, then the data each purpose needs, and not the other way round.
- Check which of the three regimes the same record falls under at the same time.
- Keep one written record of purposes that all three notices are generated from.
This page describes what the registers say and what is common practice. It is a reading of published sources, not legal advice, and it is not a compliance verdict.
Does this apply to us
- Do personal data rules apply to an online marketplace?
- Do personal data rules apply to an online seller?
- Do personal data rules apply to a manufacturer?
- Do personal data rules apply to an importer?
- Do personal data rules apply to a cloud provider?
Related comparisons
- AI rules compared: EU, United States and China
- Cross-border data transfers compared: EU, United States and China
- Cybersecurity duties compared: EU, United States and China
- Health data compared: GDPR, HIPAA and PIPL
- Online platform duties compared: EU, United States and China
- Online consumer rights compared: EU and United States
- Product safety and market access compared: EU and China
- Climate and emissions reporting compared: United States and the EU
- Export controls compared: China and the EU market side
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.