Data compliance is a regulatory framework that governs how organizations collect, store, process, and protect personal information under laws such as GDPR, HIPAA, and CCPA. Each of those three regimes was drafted for a different reason, applies to a different population, and assigns penalties using a different formula. A US hospital handling appointment data for a French patient sits inside all three at once, and the obligations do not always line up cleanly. This guide maps the three regulations side by side so that legal, security, and product teams can see where the requirements converge, where they diverge, and which clauses tend to govern an overlapping case.
What Data Compliance Means for Organizations
Data compliance is the obligation to handle personal information in line with statutory rules, contractual commitments, and supervisory-authority guidance. It sits adjacent to security but is not interchangeable with it. Security controls protect data from unauthorized access; a regulatory compliance framework dictates which data may be collected in the first place, who may see it, how long it may be retained, and what the subject of that data can demand back from the controller. A well-engineered firewall does not satisfy GDPR if the underlying processing has no lawful basis for processing.
The three regulations covered here govern overlapping but distinct populations.
- GDPR (General Data Protection Regulation): any personal data of individuals in the European Union, regardless of where the processor is established.
- HIPAA (Health Insurance Portability and Accountability Act): protected health information held by US healthcare covered entities and their business associates.
- CCPA (California Consumer Privacy Act, as amended by the CPRA): personal information of California residents collected by qualifying businesses.
GDPR: Data Compliance Obligations for EU Personal Data
Data compliance under the General Data Protection Regulation begins with territorial reach. GDPR applies to any controller or processor handling personal data of individuals located in the EU, whether the organization is headquartered in Berlin or Bangalore. Article 6 requires a documented lawful basis for processing before any personal data is touched: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Special-category data such as health or biometric records adds the Article 9 conditions on top.
Controllers must appoint a Data Protection Officer (DPO) when their core activities involve large-scale monitoring or large-scale processing of special-category data, per Article 37. Breach notification under Article 33 requires the controller to inform the lead supervisory authority within 72 hours of becoming aware of a personal data breach likely to risk individuals' rights. Cross-border data transfer outside the European Economic Area requires an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules, and after the Schrems II ruling controllers must also run a transfer impact assessment. The intersection of GDPR with model-training pipelines deserves separate attention; the operational fallout is mapped in AI impact on data privacy.
Chapter III of GDPR codifies eight rights that any EU data subject rights can exercise against a controller.
- Right to be informed (Articles 13 and 14)
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure, also called the right to be forgotten (Article 17)
- Right to restrict processing (Article 18)
- Right to data portability (Article 20)
- Right to object, including to direct marketing (Article 21)
- Rights related to automated decision-making and profiling (Article 22)
These data subject rights carry one-month response deadlines under Article 12, extendable by two further months for complex requests.
HIPAA: Data Compliance Rules for Health Information
Data compliance under the Health Insurance Portability and Accountability Act is organized around three federal rules administered by the US Department of Health and Human Services. HIPAA reaches two classes of regulated party: covered entities (health plans, healthcare providers that transmit electronic claims, and healthcare clearinghouses) and business associates (vendors that create, receive, maintain, or transmit protected health information on behalf of a covered entity). A business associate agreement is required before any PHI moves between the two, and the contract terms themselves are dictated by 45 CFR ยง 164.504(e).
The three operative rules carry distinct obligations.
- Privacy Rule (45 CFR Part 164, Subpart E): sets national standards for the use and disclosure of PHI, the minimum-necessary standard, and patient access rights to their own records.
- Security Rule (45 CFR Part 164, Subpart C): requires administrative, physical, and technical safeguards for electronic PHI, including access control, audit logs, integrity controls, and transmission security. The HHS Security Rule guidance details the addressable versus required specifications.
- Breach Notification Rule (45 CFR ยงยง 164.400 to 414): imposes a tiered breach notification requirement, with individual notice required without unreasonable delay and in no case later than 60 days, plus HHS Secretary notification on the same timeline for breaches of 500 or more records.
HIPAA civil monetary penalties tier from a four-bracket structure based on culpability, ranging from unknowing violations at the low end to willful neglect uncorrected at the high end, with annual caps adjusted periodically for inflation.
CCPA: Data Compliance Rights for California Consumers
Data compliance under the California Consumer Privacy Act, as expanded by the California Privacy Rights Act, applies to for-profit businesses that collect California residents' personal information and meet one of three thresholds: annual gross revenue above USD 25 million, buying or selling or sharing personal information of 100,000 or more California consumers or households per year, or deriving 50 percent or more of annual revenue from selling or sharing personal information. The thresholds are independent; meeting any one triggers full applicability under Civil Code ยง 1798.140(d).
Consent management under CCPA is structured around an opt-out model rather than the GDPR opt-in default. Businesses that sell or share personal information must post a Do Not Sell or Share My Personal Information link and honor Global Privacy Control browser signals, per regulations issued by the California Privacy Protection Agency. Statutory consumer rights center on four pillars.
- Right to know what personal information is collected and how it is used or disclosed (ยง 1798.100, ยง 1798.110, ยง 1798.115)
- Right to delete personal information held by a business (ยง 1798.105)
- Right to correct inaccurate personal information (ยง 1798.106, added by CPRA)
- Right to opt out of the sale or sharing of personal information, and to limit use of sensitive personal information (ยง 1798.120, ยง 1798.121)
The California Attorney General and the California Privacy Protection Agency share enforcement, with reference materials at the California AG CCPA portal. The broader operating model that places these consumer rights inside an organizational program is set out in data governance in cybersecurity.
Comparing Data Compliance Regulations: Scope and Penalties
Setting the three regulations against the same axes is the fastest way to see where a single dataset is governed by more than one regime. The table below summarizes the dimensions that most often drive program design: who is covered, what data is in scope, the maximum penalty exposure, the breach notification requirement, the privacy-officer obligation, and whether the regulatory compliance framework defaults to consent or opt-out. For a deeper head-to-head between the two most often confused regimes, see GDPR and HIPAA compliance compared.
| Dimension | GDPR | HIPAA | CCPA / CPRA |
|---|---|---|---|
| Territorial scope | EU data subjects worldwide | US covered entities and business associates | California residents |
| Data in scope | All personal data | Protected health information | Personal information of consumers |
| Max statutory penalty | 4% of global annual turnover or EUR 20 million | Tiered civil monetary penalties with annual caps per violation category | USD 2,500 per violation; USD 7,500 per intentional violation |
| Breach notification window | 72 hours to supervisory authority (Article 33) | Within 60 days of discovery (45 CFR ยง 164.404) | No fixed statutory window; reasonable security and private right of action under ยง 1798.150 |
| Privacy officer | DPO required in defined cases (Article 37) | Privacy Officer and Security Officer required (ยง 164.530, ยง 164.308) | No mandated officer; accountable contact for consumer requests required |
| Consent model | Lawful basis required, often opt-in consent | Authorization required for non-treatment uses | Opt-out for sale or sharing; opt-in for minors under 16 |
The privacy by design principle, codified in GDPR Article 25, has no direct analog in HIPAA or CCPA, but the Security Rule's required risk analysis and the CPRA's data-minimization mandate push in the same direction. Programs designed against the strictest column of the table tend to satisfy the others by construction.
Common Data Compliance Challenges and How to Address Them
Data compliance failures in mature organizations rarely stem from ignorance of the law. They stem from operational gaps between policy, data flows, and vendor relationships. The six patterns below appear repeatedly in supervisory-authority enforcement actions and in the OWASP Top 10 Privacy Risks, alongside the federal guidance published by CISA on data protection.
- Multi-jurisdiction overlap. A single SaaS product can fall under GDPR, HIPAA, and CCPA simultaneously. Map each data element to all applicable regimes before designing a control, and default to the strictest requirement on each axis.
- Data inventory gaps. Subject-access and deletion requests cannot be honored against systems that no one has cataloged. A maintained Record of Processing Activities (Article 30) doubles as the inventory of record for CCPA disclosure requirements.
- Consent management at scale. Cookie banners that lump analytics and advertising together fail GDPR's granularity test and CPRA's purpose-specification rule. Deploy a tag-management layer that gates third-party scripts on each consent category.
- Cross-border data transfer restrictions. Schrems II requires a transfer impact assessment for any export to a third country. Document the destination, the legal mechanism, and supplementary measures such as encryption with keys held in the EEA.
- Evolving data retention policy requirements. Storage-limitation rules under GDPR Article 5(1)(e) clash with sectoral retention mandates such as HIPAA's six-year documentation requirement. Build per-data-category schedules rather than a single retention default.
- Vendor and third-party risk. A controller remains liable for processor misconduct. Run a data privacy impact assessment before onboarding any processor that handles special-category data or PHI, and require contractual flow-down of the relevant statutory obligations.
Building a Data Compliance Program: Key Steps
Data compliance programs that hold up under audit share a common spine: a defensible inventory, a clear assignment of regulatory ownership, embedded privacy controls, and rehearsed incident response. The sequence below works for organizations starting from scratch and for teams retrofitting an established product. The control catalog in NIST SP 800-53 Rev. 5 and the management-system structure of ISO/IEC 27701 both provide compatible scaffolding. See also: Encryption. See also: What Is Digital Identity? Managing Privacy.
- Conduct a data inventory and mapping exercise. Catalog what personal data exists, where it lives, who can access it, and which downstream systems receive copies. This artifact anchors every later step.
- Identify applicable regulations by geography and data type. Cross-reference the inventory against the residence of data subjects, the sectoral nature of the data, and revenue thresholds.
- Appoint a Data Protection Officer or privacy officer where required. GDPR mandates a DPO in defined cases; HIPAA requires both a Privacy Officer and a Security Officer. Even where no statute compels appointment, accountable ownership shortens incident response.
- Embed privacy by design in product development. Default settings should minimize data collection, restrict secondary use, and surface consent management controls to the user. Treat these as functional requirements, not legal afterthoughts.
- Establish data retention policy schedules per data category. Encode the schedule in the storage layer so that deletion is automatic rather than discretionary.
- Build and rehearse a breach response plan. Predefine the assessment workflow, the notification templates, the supervisory-authority contact list, and the decision criteria for the 72-hour GDPR clock and the 60-day HIPAA clock. The plan is only useful if the on-call rotation has run it.
A program that survives its first regulator inquiry is one where the inventory matches reality, the retention schedule is enforced in code, and the breach playbook has been exercised at least twice in tabletop form.
Further reading
Frequently Asked Questions
How does GDPR differ from HIPAA in terms of scope?
GDPR applies to any organization processing EU residents' personal data regardless of industry, while HIPAA applies only to US-based healthcare covered entities and their business associates handling protected health information. GDPR's territorial reach is broader and its consent requirements are stricter, but HIPAA imposes heavier per-violation penalties for certain breach categories.
What are the penalties for failing to meet compliance program requirements under GDPR, HIPAA, and CCPA?
GDPR fines reach up to 4 percent of global annual turnover or 20 million euros, whichever is higher. HIPAA civil penalties follow a four-tier structure keyed to culpability, with annual caps per identical violation category that are periodically adjusted for inflation. CCPA statutory damages run from USD 100 to USD 750 per consumer per incident for the private right of action under ยง 1798.150, and administrative penalties reach USD 2,500 per violation or USD 7,500 per intentional violation. Actual enforcement outcomes vary based on cooperation and remediation.
How can an organization determine which compliance posture regulations apply to it?
Applicability turns on three factors: where the data subjects are located (GDPR for EU residents), what type of data is handled (HIPAA for PHI in US healthcare contexts), and the organization's revenue or data-volume thresholds (CCPA for California-resident data above set business-size criteria). Organizations operating across multiple jurisdictions typically need to satisfy the strictest overlapping requirement on each axis.








