Home
GDPR, LGPD, and CCPA: What Are These Laws, Similarities, and Differences

GDPR, LGPD, and CCPA: What Are These Laws, Similarities, and Differences

3 years ago
João Bruno Soares
6 minutes

LGPD, GDPR, and CCPA are data privacy regulations like so many others that are coming into force.
And, like all regulations, their text is long and detailed.

To simplify understanding, we've outlined the key similarities and differences. There are six main differences:

1. Applicable Territory

  • LGPD applies throughout Brazilian territory.
  • GDPR is applicable across the entire European Union.
  • CCPA is specific to the state of California, USA. It's important to note that only data subjects residing in California fall under this law; in other words, the law applies to anyone doing business in the state.

The California law is also the one with the most detail behind it — revenue thresholds, the "sale" versus "sharing" distinction, and two mandatory links on the homepage. We cover all of it in our guide to the CCPA and cookies.

However, it's a misconception to think that these regulations are mere replicas of each other just because they concern data protection and privacy. Compliance with one doesn't guarantee compliance with the others.

2. Scope of Data Subjects

  • GDPR applies to personal data of data subjects, which includes users, whether they are customers or mere visitors to a website.
  • CCPA applies to consumers, households, and residents.

3. Definition of Personal Data

  1. For LGPD, personal data refers to any information related to an identified or identifiable person. Some information doesn't personally identify you; you remain anonymous. However, other information, like names, emails, and personal documents, can identify you individually.
  2. For CCPA, personal data is any information that individually identifies a person or household. Anonymous data is not considered personal.
  3. For GDPR, all of the above is considered personal data. There are even two distinct categories: data made public by the data subject and data related to nonprofit organizations.

Among these definitions of personal data, there's a more special category: sensitive data.

Sensitive data includes information revealing racial or ethnic origin, political beliefs, religious or philosophical affiliations, union membership, and matters related to health and sexuality.

Unlike LGPD and CCPA, GDPR prohibits the use of sensitive data unless such use is provided for by law.

4. Data Controllers

LGPD and GDPR, within their respective territories, apply to all data processing except for personal use. Whether it's a company, NGO, or government institution, the law applies.

CCPA is different in this regard. It specifically applies to:

  1. Companies with an annual gross revenue exceeding $25 million.
  2. Companies that obtain data from more than 50,000 consumers, households, or devices.
  3. Companies that generate over 50% of their revenue from selling personal information.

5. Sale of Personal Data

In LGPD and GDPR, the sale of personal data requires a legal basis prescribed by the law. It's not something anyone can do.

On the other hand, CCPA doesn't prohibit the sale of data. It only provides the option for the data subject to opt out of having their data sold. In other words, a person can agree or disagree with the sale of their data, and the company must respect that choice.

6. Fines and Penalties

GDPR, LGPD, and CCPA impose different fines and penalties, so each one should be consulted separately. In this article, you can find more details about LGPD fines and penalties.

We've already seen that there are significant differences between the three regulations. So, what are the similarities?

Similarities Among LGPD, GDPR, and CCPA

1. Transparency About Data Use

All three regulations ensure transparency regarding data usage, including whether data is being processed, whether it can be sold, and the purpose behind these actions.

2. Power to Update and Delete Data

All three regulations allow users to revoke data consent and ensure they can update their data whenever they wish.

3. Regulatory Authority

The regulations establish a governmental authority to ensure compliance. In the case of LGPD, it's the National Data Protection Authority. For CCPA, it's the Attorney General of the State of California.

Do I Need to Comply with All Three Laws?

As discussed in the previous sections, the laws apply to their respective territories. If your company handles data from Californians and Brazilians, you need to be fully aware of CCPA and LGPD. If your company processes data of European Union customers, GDPR compliance is necessary.

However, in practice, this is simpler. Since LGPD is based on GDPR, it's easy to align with both regulations. Given that all three are based on principles of transparency and consent, three steps will ensure that your website doesn't run into issues with any of these laws.

3 Steps to Comply with LGPD, GDPR, and CCPA

1. Understand Consent and Transparency

One thing LGPD, GDPR, and CCPA have in common is their emphasis on transparency and consent, which underpin the entire law.

What does this mean in practice?

Every user needs to know that their data is being collected and for what purpose your company will process this data. This information needs to be explicit. Knowing this, the user needs to agree. This is transparency and consent.

If the user doesn't agree to data processing, they should be able to express this decision clearly and directly. Your company should respect this choice without pressuring the user to provide data.

However, manually managing this process would make operations for any company complex. To streamline this service, we move on to the second step.

2. Install a Cookie Banner

A cookie banner is a text notice, similar to what you saw when entering this blog. The cookie banner informs the user that the site collects data and requests the user's consent for data collection. The cookie banner also explains the purpose of collecting this information.

Most importantly, it records all of this. We can prove which data you agreed to provide, which is crucial for legal compliance. Moreover, through the cookie banner, you can specify which data you want to provide and which you don't, or even refuse to provide any information. And that's perfectly fine.

To ensure this operation runs smoothly, LGPD, GDPR, and CCPA require that each company has a responsible person. This professional is called a DPO: Data Protection Officer, which is the third step.

3. Appoint a DPO

DPO stands for Data Protection Officer. Your company can outsource this service or select an internal employee for this role.

The DPO is legally responsible for the company's data protection policy, acting as the liaison between the company and the data protection authority. In the case of LGPD, this authority is the ANPD. For CCPA, it's the Attorney General of California.

With these best practices, your company is assured in this ever-changing landscape and extensive debate on data usage.

Tags

GDPR
Data Protection Officer - DPO

Related posts

AdOpt post

GDPR and Cookies all you need to know

Understanding the General Data Protection Regulation (GDPR) and its impact on cookies is essential. So, let's break it down, step by step.

AdOpt post

How to Choose a CMP (Consent Management Platform)?

Using a CMP (Consent Management Platform) is a great way to make efforts to adapt to new privacy regulations like GDPR, LGPD, DPDPA, CCPA and more...

AdOpt post

Virginia VCDPA: Privacy Policy

What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

Outsourcing the DPO (DPOaaS), Is It a Good Idea?

The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

The Differences Between Data Controller and Data Processor - LGPD

Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

Fines in LGPD - What are they, amounts, and compliance deadlines

In this article, we will answer all your questions regarding fines under the LGPD (Brazil's General Data Protection Law).

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

Axeptio Strengthens its International Expansion with the Acquisition of AdOpt

Axeptio acquires Brazil's AdOpt, expanding global reach in consent management and LGPD compliance.

AdOpt post

ROPA in LGPD? Get to Know the Records of Processing Activities.

Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

How to delete cookies and cache in Chrome and other browsers?

Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

Understand the meaning of the LGPD for your company

Surely you've already seen the predictions of fines and sanctions, processes. But, what does it mean to your company?

AdOpt post

IOWA ICDPA: Privacy Policy

What the Iowa ICDPA requires from your Privacy Policy: five mandatory elements, 90-day response deadline, 60-day appeal process, opt-out for sensitive data, no retention periods required, and the 90-day cure period.

AdOpt post

Everything about the Brazilian LGPD - General Data Protection Law.

All the important information about the General Data Protection Law - LGPD: what it is, why it exists, how it works, when it came into force, who it applies to, potential fines, steps for compliance, and its legal principles.

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

AdOpt CMP

AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode

AdOpt post

Key Differences between LGPD and GDPR and the Impact on Internet Cookies

While both regulations share the goal of safeguarding individuals' rights regarding the processing of their personal data, there are some important differences between them. It is crucial to understand these distinctions and their implications, particularly in the context of internet cookies.

AdOpt post

10 Marketing Processes You Should Rethink under the LGPD!

In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Virginia VCDPA: Cookies Policy

What the Virginia VCDPA requires from your Cookies Policy: targeted advertising disclosure, consent standards, tracker categories, opt-out mechanisms, and the 30-day cure period explained.

AdOpt post

Colorado CPA: DSAR Privacy Portal

How to handle DSARs under the Colorado CPA: 5 consumer rights, portability limited to twice per year, Universal Opt-Out Mechanism, 24-month record retention, and District Attorney enforcement.

AdOpt post

Data Protection Officer and LGPD, a Solitary or Teamwork Job?

How do you deal with a profession that didn't even exist a few years ago and is now mandatory in companies? That's precisely the question that arises when we think of the figure of the Data Protection Officer or DPO.

AdOpt post

Oregon OCPA: DSAR Privacy Portal

Oregon OCPA DSAR guide: the L.O.C.K.E.D. rights, opt-out without authentication, derived data in deletion scope, 15-day revocation deadline, GPC from January 2026, and the elimination of the cure period.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Data Mapping or Data Inventory - a life jacket for the DPO!

With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.

AdOpt post

Connecticut CTDPA: DSAR Privacy Portal

How to handle DSARs under the Connecticut CTDPA: 5 consumer rights, opt-outs without mandatory authentication, 60-day appeal deadline, 15-day consent revocation, and AG-only enforcement.

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

Responsibilities of a data protection officer.

Drawing an analogy from the world of soccer, we can think of the DPO as the "midfielder" of the team, responsible for connecting the defense and the attack.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

California CCPA: Cookies Policy

What the California CCPA/CPRA requires from your Cookies Policy: Do Not Sell or Share link, GPC compliance, sale vs sharing distinction, sensitive PI opt-out, and annual updates.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪