Data Privacy Regulations: GDPR, CCPA, HIPAA Explained
Meta paid €1.2 billion. One fine. One case. The Irish Data Protection Commission issued it in May 2023 for shipping EU user data to US servers without adequate safeguards — and it still holds the record as the largest GDPR penalty ever handed down.
Photo by Ann H on Pexels
Here's the deal though. You're probably not Meta. But if your company collects an email address, tracks a website visitor, or stores a patient's appointment date, at least one of these three laws applies to you. And most businesses find that out the expensive way — usually about six weeks after somebody in legal forwards them a letter.
This guide is written for people who need answers fast: startup founders, marketing leads, small clinic administrators, and anyone who just got a compliance question dropped on them and has no idea where to start.
What you'll learn:
- Which of the three laws actually applies to your business (the scope tests are narrower than you'd guess)
- The exact rights each law hands to consumers — and your deadline to respond to each request
- A 7-step compliance framework you can start on Monday morning
No legalese. No hand-waving. Let's go.
Why This Stuff Hits Harder in 2026
Enforcement stopped being theoretical around 2023. Since then, regulators have moved from politely worded warning letters to structural penalties — fines calculated as a percentage of global revenue, mandatory data deletion orders, and in HIPAA's case, actual criminal referrals.
The numbers back this up. The European Data Protection Board has tracked over €5.8 billion in cumulative GDPR fines since 2018. California's Attorney General and the newer California Privacy Protection Agency have both opened enforcement sweeps aimed at companies ignoring "Do Not Sell" requests. And the HHS Office for Civil Rights resolved more HIPAA enforcement actions in the last three years than in the entire decade before it.
Honestly, any guide covering GDPR, CCPA, and HIPAA has to open with the uncomfortable part — compliance is now a line item, not a nice-to-have. You budget for it the same way you budget for accounting.
Three Misconceptions That Cost Companies Real Money
"We're a US company, so GDPR doesn't apply." Nope. GDPR follows the data subject, not the company. If you offer goods or services to people in the EU — or monitor their behavior with analytics cookies — you're in scope. Article 3(2) spells it out.
"We don't sell data, so CCPA doesn't apply." Also wrong, or at best incomplete. CCPA's definition of "sale" includes sharing personal information for "other valuable consideration." Handing visitor data to an ad network in exchange for better targeting? Congratulations, that's a sale under the statute. The CPRA amendments then piled on a separate "sharing" category for cross-context behavioral advertising.
"HIPAA covers all health data." It really doesn't. HIPAA only covers protected health information held by covered entities and their business associates. Your fitness tracker data? Generally not HIPAA-protected. That one surprises people constantly, and I've watched founders visibly deflate when they learn it — usually right after they built a marketing page around "HIPAA-grade privacy."
Look, these three laws overlap in genuinely messy ways. A telehealth startup in Austin serving EU expats can trip all three at once.
Photo by Ann H on Pexels
Core Concepts: What Each Law Actually Regulates
Before the compliance steps, you need the vocabulary. Getting GDPR, CCPA, and HIPAA straight means knowing what each law calls things, because the terms don't map cleanly across jurisdictions. Same concept, three different names, three slightly different definitions. Fun.
The Three Laws at a Glance
| Dimension | GDPR | CCPA / CPRA | HIPAA |
|---|---|---|---|
| Full name | General Data Protection Regulation | California Consumer Privacy Act (as amended by CPRA) | Health Insurance Portability and Accountability Act |
| Effective | May 25, 2018 | Jan 1, 2020 (CPRA amendments Jan 1, 2023) | Privacy Rule: April 14, 2003 |
| Geographic scope | EU/EEA data subjects, worldwide reach | California residents | United States |
| Who it binds | Controllers and processors | For-profit businesses meeting thresholds | Covered entities + business associates |
| Data covered | Any "personal data" | "Personal information" (broad, household-level) | Protected Health Information (PHI) |
| Max penalty | €20M or 4% global annual revenue, whichever is higher | $2,663 per violation; $7,988 per intentional or minor-related violation | $2.1M per violation category per year (tiered, inflation-adjusted) |
| Private lawsuits? | Yes (Art. 82) | Limited — data breach only | No private right of action |
| Regulator | National DPAs + EDPB | California AG + CPPA | HHS Office for Civil Rights |
Penalty figures reflect inflation-adjusted amounts as published in the Federal Register and CPPA regulations. They shift every year, so check the source before you drop them into a board deck and get corrected in front of your CFO.
Key Terminology You'll Actually Use
Controller vs. Processor (GDPR). The controller decides why and how data gets processed. The processor just follows instructions. Run a SaaS product? You're usually a processor for your customers' data and a controller for your own marketing list — simultaneously, in the same company, sometimes in the same database. Both roles carry obligations; the controller carries more.
Business vs. Service Provider (CCPA). Roughly parallel to controller/processor, but not identical. A service provider needs a written contract restricting data use — without it, the transfer flips into a "sale" and triggers opt-out obligations you didn't plan for.
Covered Entity vs. Business Associate (HIPAA). Covered entities are health plans, healthcare clearinghouses, and providers who transmit health info electronically. Business associates are the vendors handling PHI on their behalf — your cloud host, your billing service, your transcription vendor. Every single one needs a signed BAA (Business Associate Agreement). No exceptions, no handshake deals.
Lawful basis (GDPR only). You can't process EU personal data just because you feel like it. Article 6 lists six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Pick one before you collect. Write it down.
Honestly? That last point trips up more companies than everything else combined. Consent isn't the default — it's frequently the worst basis you can pick, because someone can yank it back at any moment and you have to stop cold.
Consumer Rights, Side by Side
| Right | GDPR | CCPA/CPRA | HIPAA |
|---|---|---|---|
| Access your data | Yes (Art. 15) | Yes | Yes (right of access) |
| Delete your data | Yes (Art. 17) | Yes, with exceptions | Limited (amendment right instead) |
| Correct inaccuracies | Yes (Art. 16) | Yes (added by CPRA) | Yes (right to amend) |
| Data portability | Yes (Art. 20) | Yes | Yes (electronic copy) |
| Opt out of sale/sharing | N/A (consent-based) | Yes | N/A |
| Limit sensitive data use | Via lawful basis | Yes (CPRA addition) | Via minimum necessary rule |
| Response deadline | 1 month (extendable to 3) | 45 days (extendable to 90) | 30 days (one 30-day extension) |
Look at those deadlines. One month, 45 days, 30 days — three different clocks, and mixing them up is exactly how companies end up non-compliant on a technicality rather than on anything substantive.
The 7-Step Compliance Framework
This is the practical core. Definitions are fine, but nobody ever passed an audit by knowing what "controller" means — so here's the sequence that actually works.
Step 1: Map Your Data
You can't protect what you can't find. Build a data inventory covering:
- What personal data you collect (fields, not categories — "email address," not "contact info")
- Where it lives (which database, which SaaS tool, which spreadsheet on someone's laptop)
- Why you collect it (this becomes your lawful basis under GDPR)
- Who you share it with (every vendor, every integration, every pixel)
- How long you keep it
Concrete example: A 30-person e-commerce company ran this exercise and found customer data sitting in 14 systems. They'd confidently estimated 5. The nine surprises included a legacy Mailchimp list, a spreadsheet parked in a former employee's Drive folder, and a customer support tool nobody had logged into since 2022. That last one still had 8,000 records in it.
Start with a spreadsheet. Seriously. You do not need software for this yet, and every vendor who tells you otherwise is selling something.
Step 2: Figure Out Which Laws Apply
Run each scope test:
GDPR applies if you're established in the EU/EEA, OR you offer goods/services to people there, OR you monitor their behavior. Google Analytics running on a page that gets EU traffic counts as monitoring.
CCPA applies if you do business in California AND clear one of three thresholds: (a) gross annual revenue over $25 million, (b) buying, selling, or sharing personal information of 100,000+ California consumers or households, or (c) pulling 50%+ of annual revenue from selling or sharing personal information.
HIPAA applies if you're a covered entity or you handle PHI on behalf of one. Not sure? Ask yourself one question: do I receive health data from a provider, plan, or clearinghouse? If yes, you're probably a business associate.
Then check your own state. As of 2026, roughly 20 US states have comprehensive privacy laws in effect — Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of others. Most crib loosely from the CCPA template. Our guide to state-level privacy laws breaks down where they diverge.
Step 3: Establish a Lawful Basis for Each Processing Activity
For GDPR, go activity by activity. No shortcuts:
| Activity | Typical lawful basis |
|---|---|
| Fulfilling an order | Contract (Art. 6(1)(b)) |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Fraud detection | Legitimate interests (Art. 6(1)(f)) |
| Tax record retention | Legal obligation (Art. 6(1)(c)) |
| Analytics cookies | Consent (per ePrivacy Directive) |
Leaning on legitimate interests? Then run a Legitimate Interests Assessment — a documented balancing test weighing your interest against the individual's rights. Regulators ask for these. Routinely. And "we discussed it internally" is not an assessment.
Step 4: Fix Your Privacy Notice
Both GDPR (Articles 13–14) and CCPA demand specific disclosures. Your notice has to state:
- Who you are and how to contact you (plus DPO contact if you have one)
- What categories of data you collect
- Why you collect it, and your lawful basis
- Who you share it with (categories of recipients, at minimum)
- How long you retain it
- What rights people have and how to exercise them
- How to complain to a regulator
CCPA tacks on one more: if you sell or share data, you need an unmissable "Do Not Sell or Share My Personal Information" link on your homepage.
Write it in plain language. GDPR Article 12 literally uses the words "clear and plain language." A wall of legalese isn't just bad UX — it's its own violation. Fun fact: the average privacy policy reads at a college level, which is roughly four grades above the average news article. That gap is the whole problem in one statistic.
Step 5: Build a Rights Request Workflow
Someone emails asking for their data. What happens next? If the honest answer is "it lands in a shared inbox and somebody eventually notices," you have a problem with a 45-day fuse on it.
Build the process:
- Intake — a dedicated email alias or web form, monitored daily
- Identity verification — proportionate to how sensitive the data is (don't demand a passport scan for an email unsubscribe)
- Search — query every system in your data map
- Review — apply exemptions (legal holds, other people's data, trade secrets)
- Respond — within the applicable deadline, in a portable format
- Log — record every request, every decision, every date
That log is your evidence during an investigation. Without it, you're asking a regulator to take your word for it.
Step 6: Lock Down Vendors and Transfers
Every vendor touching personal data needs paper:
- GDPR: Data Processing Agreement under Article 28
- CCPA: Service provider contract with use restrictions
- HIPAA: Business Associate Agreement
For EU-to-US transfers you need a valid mechanism. The EU-US Data Privacy Framework (adequacy decision, July 2023) covers certified US companies. Otherwise it's Standard Contractual Clauses plus a Transfer Impact Assessment.
Step 7: Ship Security Controls and a Breach Plan
GDPR Article 32 asks for "appropriate technical and organisational measures," which is delightfully vague. HIPAA's Security Rule goes the other direction — administrative, physical, and technical safeguards, each with required and addressable specifications spelled out.
Baseline controls that satisfy all three:
- Encryption at rest and in transit
- Role-based access control with least privilege
- Audit logging (HIPAA requires this outright)
- Multi-factor authentication on every admin account
- Documented incident response plan with breach notification steps
Breach deadlines are all different, of course. GDPR: 72 hours to the supervisory authority. HIPAA: 60 days to affected individuals; breaches hitting 500+ people go to HHS within 60 days, smaller ones roll up annually. CCPA has no general notification duty, but California's separate breach law absolutely does.
Write the plan now, while nothing is on fire. During an actual breach, nobody in the building is calm enough to invent one from scratch at 2am.
Common Mistakes to Avoid
After watching plenty of companies stumble through this, here are the failures that keep repeating.
1. Treating consent as a catch-all. Consent under GDPR must be freely given, specific, informed, and unambiguous — and just as easy to withdraw as it was to give. Pre-ticked boxes are dead. Cookie walls that block access unless you accept everything generally don't survive either. And once someone withdraws, you stop. Immediately.
2. Ignoring vendors and subprocessors. Your compliance ceiling is set by your sloppiest vendor. The 2023 MOVEit breach tore through hundreds of organizations via a single file-transfer tool — and every downstream company was still on the hook for notifying its own customers. "Our vendor got hacked" is context, not a defense.
3. Over-collecting "just in case." Data minimization is an actual legal requirement (GDPR Article 5(1)(c), HIPAA's minimum necessary standard), not a design preference. Every extra field is extra liability sitting on your servers. That optional "date of birth" on your signup form? If nothing in your product uses it, kill it.
4. No retention schedule. Hoarding data forever violates storage limitation principles and turns a small breach into a catastrophic one. Set retention periods per data category, then automate the deletion. My hot take: a retention policy is the single highest-ROI compliance work most companies skip, because it permanently shrinks your risk surface instead of just documenting how big it is. Everyone buys the consent banner first. That's backwards.
5. Confusing HIPAA scope. Employers holding employee health records generally aren't covered entities for that data — the Americans with Disabilities Act and state laws step in instead. Meanwhile, a wellness app is covered if it's bolted onto a group health plan. Get this determination in writing from counsel, because the intuition here is wrong more often than it's right.
6. Missing the DPIA trigger. GDPR Article 35 requires a Data Protection Impact Assessment for high-risk processing — large-scale profiling, systematic monitoring of public areas, processing sensitive categories at scale. Skipping a required DPIA is itself an infringement, entirely separate from whatever the processing did.
7. Assuming a policy equals compliance. A gorgeous privacy notice with zero operational backing is worse than useless — it's a documented promise you're actively breaking, in writing, on your own website. Regulators line up what you say against what you do. That comparison is basically the whole investigation.
Photo by Pixabay on Pexels
Real-World Cases Worth Studying
Three cases that show how these rules actually land when someone gets caught.
Case 1: Amazon's €746 Million GDPR Fine (Luxembourg, 2021)
Luxembourg's CNPD hit Amazon with €746 million over advertising practices — processing personal data for targeted ads without valid consent. The lesson isn't the number. It's the basis: Amazon argued legitimate interests for behavioral advertising, and the regulator flatly disagreed. Behavioral advertising almost always requires consent in the EU. Almost always. Plan accordingly.
Case 2: Sephora's $1.2 Million CCPA Settlement (California, 2022)
California's first public CCPA enforcement action. Sephora ran third-party analytics and advertising trackers, which the AG characterized as a "sale" of personal information. Three failures stacked up: no disclosure of the sale, no "Do Not Sell" link, and no honoring of Global Privacy Control signals.
That GPC point deserves more attention than it gets. Browser-level opt-out signals are legally binding in California. If your site ignores them, you're non-compliant no matter how beautiful your cookie banner is. I'd argue this is the most under-implemented requirement in the entire CCPA — plenty of sites with immaculate consent UX are quietly failing it right now.
Case 3: A Small Clinic's $100,000 HIPAA Settlement
HHS OCR has settled repeatedly with small practices — typically somewhere between $10,000 and $250,000 — over failures that sound almost boring: no risk analysis on file, PHI sitting on an unencrypted laptop, patient records not handed over within 30 days.
The pattern holds across settlements. Small organizations get penalized less for sophisticated attacks and more for missing paperwork. A documented risk analysis is the single most-cited absent control in OCR settlements, year after year. It's also, irritatingly, one of the cheapest things on this entire list to produce.
For the mechanics of breach response, see our incident response guide.
Official Tools and Resources
Free, authoritative, zero vendor pitch attached.
GDPR:
- Full regulation text (EUR-Lex) — the actual law, searchable by article
- European Data Protection Board guidelines — official interpretive guidance and enforcement decisions
- EU Commission's data protection portal — plain-language explanations for businesses
CCPA/CPRA:
- California Attorney General's CCPA page — FAQs, regulations, enforcement announcements
- California Privacy Protection Agency — rulemaking updates and current regulatory text
HIPAA:
- HHS HIPAA for Professionals — Privacy Rule, Security Rule, and Breach Notification Rule guidance
- HHS Security Risk Assessment Tool — free downloadable tool built for small practices
Cross-cutting:
- NIST Privacy Framework — voluntary framework that maps cleanly onto all three laws
- FTC Business Guidance on Privacy and Security — US enforcement perspective beyond the sector-specific laws
If you handle health data, start with the HHS risk assessment tool. It's genuinely good, it costs nothing, and a completed risk analysis closes the single most commonly cited HIPAA gap. Government software has a reputation, and this one quietly beats it.
Related reading: How to build a data retention policy and cookie consent requirements by region.
Frequently Asked Questions
Does GDPR apply to my US-based small business?
It can. If your site pulls EU visitors and you're running analytics or advertising trackers, you may be monitoring their behavior — which trips Article 3(2). The clearer trigger is actively targeting EU customers: pricing in euros, EU-language pages, shipping to EU addresses. Passive accessibility alone usually isn't enough on its own, but the moment analytics enters the picture, that calculation shifts.
What's the difference between CCPA and CPRA?
CPRA is an amendment, not a replacement. It took effect January 1, 2023, added correction rights and a "sensitive personal information" category with use limits, introduced "sharing" for behavioral advertising, and spun up the California Privacy Protection Agency as a dedicated enforcer. Most people still just say "CCPA" for the whole combined thing.
Can I be subject to all three laws at once?
Yes, and in healthcare tech it's routine. A telehealth platform is under HIPAA for patient data, under CCPA if it clears California thresholds, and under GDPR if it treats EU residents. Good news: the controls overlap heavily — encryption, access control, and a rights workflow do triple duty. The obligations that don't overlap are almost entirely the documentation ones, which is also where everyone gets caught.
How much does compliance actually cost?
Wildly variable, but rough ranges for a small-to-mid business: initial data mapping and gap assessment runs $5,000–$25,000 with outside help, or a few weeks of internal time if you're doing it yourself. Ongoing — consent management tooling, an outsourced DPO, annual assessments — usually lands between $10,000 and $50,000 a year. Stack that against a single CCPA violation at $2,663 per affected consumer. At 5,000 affected consumers you're already past $13 million. The math stops being a debate pretty quickly.
Do I need a Data Protection Officer?
Under GDPR, a DPO is mandatory if you're a public authority, if your core activities involve large-scale systematic monitoring, or if you process special-category data at scale. Otherwise it's optional, though plenty of companies appoint one anyway. Neither CCPA nor HIPAA requires a DPO — but HIPAA does require a designated Privacy Official and Security Official, and those roles need actual names attached.
What counts as a data breach requiring notification?
Under GDPR: any security breach leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data — reportable within 72 hours unless it's unlikely to result in risk to individuals. Under HIPAA: unauthorized acquisition, access, use, or disclosure of unsecured PHI is presumed to be a breach unless a four-factor risk assessment shows low probability of compromise. Note the word "unsecured" — properly encrypted data that walks out the door may not trigger HIPAA notification at all. That's the safe harbor, and it's the best argument for encryption you'll ever hear.
Does deleting data satisfy a deletion request completely?
Not always. Both GDPR and CCPA carve out exemptions: you can retain data needed for legal compliance, to finish a transaction, for security and fraud prevention, or to pursue legal claims. But you still have to respond, spell out what you deleted, and explain what you kept and why. Quietly deleting half of it and saying nothing isn't compliance — it's just a slower violation.
Are backups covered by deletion requests?
Technically yes, though regulators have landed somewhere pragmatic. The UK ICO accepts that data may sit in backups if you put it "beyond use" — no active access, and it disappears when the backup gets overwritten on its normal cycle. Document that rotation schedule; it's what makes the argument hold.
Key Takeaways
Strip all of this down and you get three points:
- Scope determines everything. GDPR follows EU residents anywhere on earth. CCPA has revenue and volume thresholds. HIPAA follows PHI through covered entities and their vendors. Run the tests before you spend a single dollar on tooling — most companies buy first and scope second, which is how you end up paying for a consent platform you didn't need.
- Documentation is the deliverable. Regulators rarely fine you for imperfect security. They fine you for missing risk assessments, absent lawful-basis records, unsigned vendor agreements, and unlogged rights requests. The paper trail is the product.
- The controls overlap; the deadlines don't. Encryption, access control, and a rights workflow serve all three laws at once. But 72 hours (GDPR breach), 45 days (CCPA request), and 30 days (HIPAA access) are three separate clocks. Put them in your calendar, not your memory.
Your next step: block two hours this week and build the data inventory from Step 1. Just a spreadsheet — systems, data fields, purposes, vendors, retention. Every other compliance decision hangs off that one document, and the part where you figure out what you actually have is the one part you can't outsource to anybody.
This guide is educational and isn't legal advice. Privacy law shifts constantly, and applicability depends on your specific circumstances. Talk to qualified counsel before making compliance decisions.