News & Commentary on ISO Management System Standards

    EU GDPR vs. UK GDPR vs. CCPA vs. CPRA – it can be confusing

    Global Data Protection-1- compressed

    The rights to protect personal data vary significantly from one jurisdiction to another.

    We are often asked about four similar but different regulations and statutes regarding Personal Data Protection: the EU GDPR, the UK GDPR, the CCPA, and the CPRA.

    Suppose you are part of an organization seeking GDPR compliance, CCPA compliance, or CPRA compliance. In that case, this short introduction that we put together will help you learn the basics and where else to go for additional information.

    Data Privacy Regulations: Similarities and Differences

    What we’re talking about are the four most frequently referenced pieces of Personal Data Protection legislation, which, while similar, differ significantly in their detail. They have recently changed their content and application with further changes. No wonder then that people get confused. Let’s begin with a definition …

    'Personal data' is any information about an identifiable person.

    • An identifiable person is someone who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to their physical, physiological, mental, economic, cultural, or social identity.
    • The ‘data subject’ is the title given to the person whose personal data are collected, held, or processed.
    • In the EU and worldwide, the rights of the data subject about the processing, handling, and storing of their personal data are codified in law (better in some jurisdictions than in others).
    • And must be respected by all public and private sector organizations, as well as individuals in possession and/or control of such data.


    EU GDPR (EU and EEA)

    The General Data Protection Regulation (EU GDPR) is the world's toughest privacy and security law. It applies throughout the EU and EEA area.

    Though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere globally, so long as they target or collect data related to people in the EU.

    The regulation was put into effect on May 25, 2018, and levies harsh fines against those who violate its privacy and security standards, with penalties reaching into the tens of millions of euros.

    With the GDPR, Europe is signaling its firm stance on data privacy and security at a time when more people are entrusting their personal data with cloud services, and breaches are a daily occurrence.

    The regulation itself is significant, far-reaching, and relatively light on specifics, making GDPR compliance a daunting prospect, particularly for small and medium-sized enterprises (SMEs).


    Click on the image on the left to see the table in full size, or click on the button on the right to see our GDPR Foundation Course.


    The six most common applications of GDPR are:

    1. EU PARENT COMPANY: If your parent company is registered in an EU member state, it is possible that GDPR compliance may be coordinated at that level. If so, you may be able to rely on parent company procedures.
    2. PERSONAL DATA STORED LOCALLY: Local data that may not be captured by parent company processes will likely be held. Examples might include HR/payroll and mobile phone contacts.
    3. LOCAL SUPPLIERS: You might consider formally advising local suppliers of your potential need to audit their processes for GDPR compliance, particularly where local suppliers are a vital part of the supply chain.
    4. STAFF TRAINING: Training is required for everyone in the company, regardless of the position, from the goods received clerk to the board of directors. Embedding GDPR principles in the company culture will be critical in achieving compliance. Therefore, while training is necessary, top management support is also vital.
    5. OFF-SITE STORAGE: When evaluating the results of a data audit, you should consider the status of archive documents held off-site. Particular consideration should be paid to documenting the control of such information when it is retrieved from the archive and re-introduced into the main body of company documentation.
    6. TRADING WITH NON-EU COMPANIES: If you are trading with entities in a 3rd country that does not have an adequate data protection regime, personal data transfer may only occur via a legal transfer mechanism.

     New call-to-action


    UK GDPR (United Kingdom)

    The United Kingdom General Data Protection Regulation (UK-GDPR) is the UK’s data privacy law that governs the processing of personal data from individuals inside the UK.

    The UK-GDPR was drafted due to the UK leaving the EU, which resulted in the EU’s GDPR not applying domestically to the UK any longer.

    There are very few substantial differences between the UK-GDPR and its EU equivalent.

    Essentially, the UK has lifted the entire structure of the EU GDPR and put it into UK law. However, the UK-GDPR changes key areas of the law concerning national security, intelligence services, and immigration.

    As with EU GDPR, any company or organization that processes personal data from individuals inside the UK must comply with the UK-GDPR – even if the organization isn’t itself located within the UK.

    In June 2021, the European Commission (EC) adopted two UK data adequacy decisions. These decisions mean data flows between the EU and the UK can continue, and no additional safeguards are required.

    The UK plans to introduce new legislation regarding data protection before the end of 2023 and abandon the UK-GDPR. Likely consequences will include loss of the EU data adequacy decision benefits and further disruption of UK trade with the EU.

    CTA button showing a preview of what learners can learn from deGRANDSON's EU GDPR Advanced Course for Data Protection Officers   Click on the image on the left to see the table in full size, or click on the button on the right to see our GDPR Advanced Course.

    CCPA (California)

    Personal Data Protection needs to be better developed in the USA. The most stringent relevant law is the California Consumer Privacy Act (CCPA, January 2020), a state statute intended to enhance privacy rights and consumer protection for residents of California. The law created an array of consumer privacy rights and business obligations about collecting and selling personal information.

    The Act intends to provide California residents with the right to:

    1. Know what personal data is being collected about them.
    2. Know whether their personal data is sold or disclosed and to whom.
    3. Say no to the sale of personal data.
    4. Access their personal data.
    5. Request a business to delete any personal information about a consumer collected from that consumer.
    6. Not be discriminated against for exercising their privacy rights.

    The difference between GDPR and CCPA is that the CCPA is designed to protect “consumers” who are natural persons and who must be California residents to be protected. In contrast, the GDPR protects “data subjects,” who are natural persons and does not specify residency or citizenship requirements.

    Variants of CCPA have been adopted by other States of the USA, where the individual states decide on data protection matters. A Federal solution would obviously be far more beneficial to American owners and users of personal data.

    CPRA (California)

    The California Privacy Rights Act (CPRA), also known as Proposition 24, is a ballot measure approved by California voters on Nov. 3, 2020. It significantly amends and expands the CCPA, sometimes called CCPA 2.0.   Most of the provisions of CPRA won’t become operative until Jan. 1, 2023.

    The CPRA creates two additional rights:

    1. the right to correct inaccurate personal information; and
    2. the right to limit the use and disclosure of sensitive personal information.

    Free Sample GDPR Compliance Audit form

    Click the image for a copy of our GDPR Compliance Audit Form

    What of personal data protection elsewhere in the world?

    By 2023, 65% of the world’s population will have its personal data covered under modern privacy regulations, according to Gartner, the global research organization.

    As more and more social and economic activities occur online, the importance of privacy and data protection is increasingly recognized. Collecting, using, and sharing personal information with third parties without consumers' notice or consent is of equal concern.

    Many data protection law initiatives continue to be passed and adopted. 2022 will see more European regions, the Middle East, the United States, and the Asia Pacific introducing or amending data privacy and protection laws.

    137 out of 194 countries had put in place legislation to secure data and privacy protection.

    Africa and Asia show different levels of adoption, with 61% and 57% of countries have adopted such legislation. The share in the least developed countries is only 48%.

    View our ISO 27001:2022 Courses

    For further information

    Follow these links to get detailed information and advice…

    Related Articles

    deGRANDSON Global is an ISO Certified Educational Organization

    InISO Compound Logo-2-1 - compressed October 2021, we secured certification to three education-related ISO Standards.  We now have a university-grade management system in place conforming to the requirements of  …

    • ISO 21001, Educational Organizational Management System,
    • ISO 29993, Learning Services outside formal Education,  and
    • ISO 29994, Learning Services – additional requirements for Distance Learning.

    We have chosen ISO 21001 certification because, unlike IRCA and Exemplar badges (which, in our opinion, are commercially compromised), it is based on independent third-party assessment.  It is a ‘university grade’ standard globally by schools, colleges, and universities to demonstrate competence.

    Written by Dr John FitzGerald

    Director & Founder of deGRANDSON Global. Spent 15 years in the manufacturing industry and 25 years training, consulting & auditing management systems
    Find me on:

    Subscribe to Email Updates

    Recent Posts