CCPA, LGPD, AI Act: navigating the global regulatory patchwork
GDPRGDPREU regulation governing how organizations collect, store and use personal data, with fines tied to global revenue for breaches.View full definition → gets all the press. But if your organization operates globally, or plans to, you're facing a patchwork of privacy regulations that each require attention and, critically, a compliance architecture that can serve them all without rebuilding from scratch for each one.
The global regulatory landscape
CCPA / CPRA (California, USA)
The California Consumer Privacy Act (CCPA), enhanced by the California Privacy Rights Act (CPRA), gives California consumers rights similar to GDPR: right to know, right to delete, right to opt-out of sale. Key differences from GDPR:
- Threshold-based: only applies to organizations meeting certain revenue or data volume thresholds
- Opt-out model (not opt-in): consumers can opt out of data sale, but data processing is permitted by default
- "Sale" of data is broadly defined, sharing data with third parties for commercial benefit may count as a sale
- CPRA created a dedicated California Privacy Protection Agency (CPPA) with enforcement authority
Organizations that built GDPR compliance first have a significant head start on CCPA/CPRA, many of the same mechanisms apply, with adjustments.
LGPD (Brazil)
Lei Geral de Proteção de Dados (2020) is Brazil's GDPR equivalent. Nearly identical structure: six lawful bases, data subject rights, mandatory DPO for some organizations, breach notification within a reasonable period. Key difference: enforcement is still maturing, the Brazilian National Data Protection Authority (ANPD) has been ramping up gradually and issuing its first significant fines.
India's DPDP Act
India's Digital Personal Data Protection Act was passed in 2023, but it took until 2025 for the implementing rules to be finalized, and enforcement is now being phased in. It represents one of the largest jurisdictions outside the EU to implement GDPR-like protections. It applies to any organization processing digital personal data of Indian residents. Data Fiduciary obligations under the Act are similar to those of a data controller under GDPR.
The EU AI Act
The EU AI Act, which entered into force in August 2024, is the world's first comprehensive AI regulation. It takes a risk-tiered approach:
- Prohibited AI (banned outright): Real-time biometric mass surveillance in public spaces, social scoring systems, AI that manipulates behavior exploiting vulnerabilities, AI that infers sensitive characteristics from biometrics. These bans took effect in February 2025.
- High-risk AI: AI used in critical infrastructure, education, employment, essential services, law enforcement, migration. Requires conformity assessment, registration in an EU database, human oversight mechanisms.
- Limited risk: AI like chatbots, must disclose they are AI.
- Minimal risk: No requirements.
There is also a separate set of obligations for general-purpose AI (GPAI) models, such as large foundation models, which started applying in August 2025. Most enterprise AI falls in the "high-risk" or "limited risk" categories. Every CDO operating in the EU needs an AI Act compliance audit of their AI portfolio.
GDPR Compliance: Explain Like I'm Five with Data Privacy Expert
Knowledge check
1. What is the most fundamental difference between the CCPA/CPRA consent model and the GDPR consent model?
2. An organization has already built a mature GDPR compliance program and now needs to comply with CCPA/CPRA and LGPD. What is the key strategic takeaway from the lesson?
3. Under the EU AI Act's risk-tiered approach, why does a chatbot fall into a different category than an AI system used for employment screening?
4. Select ALL categories that the EU AI Act classifies as prohibited (banned outright) AI practices.
Select all the correct answers.
5. Select ALL statements that correctly describe LGPD and India's DPDP Act as presented in the lesson.
Select all the correct answers.
Building a multi-regulation compliance architecture
The mistake: building separate compliance programs for each regulation. Separate GDPR team, separate CCPA team, separate AI Act team. This is expensive, creates inconsistencies, and doesn't scale as new regulations emerge.
The solution: a privacy compliance platform approach.
Core capabilities needed:
- Data inventory and ROPA: Centralized record of all processing activities, applicable regulations, lawful bases, and retention periods. One record, multiple regulatory lenses.
- Consent and preference management: A system of record for individual consent and preferences, queryable by regulation. Customer says "opt out" → this flows to CCPA compliance and GDPR processing simultaneously.
- Data subject rights workflow: Automated intake, routing, and fulfillment of DSARs across all systems. Must handle access, erasure, portability. Must meet deadlines (30 days for GDPR, 45 for CCPA).
- Vendor and DPA management: Track all data processors, DPA status, transfer mechanisms. Updated when vendors change.
- Privacy impact assessment (DPIA/PIA): Integrated workflow that triggers when new projects or systems are proposed, routes to DPO review, documents decisions.
Tools in this space: OneTrust, TrustArc, Osano, DataGrail. These are not cheap, but the alternative (manual compliance management across multiple regulations) is more expensive and more risky.
The CDO's role in AI Act compliance
The AI Act creates a new responsibility for CDOs: AI system inventory and risk classification. You need to know:
- What AI systems your organization uses (bought or built)
- Which risk tier each falls into under the AI Act
- What compliance obligations apply to high-risk systems
- Who is accountable for compliance for each system
This doesn't exist in most organizations today. The AI Act's obligations arrive on a staggered timeline: the prohibited-practice bans applied from February 2025, GPAI model rules from August 2025, and the bulk of high-risk system obligations apply from August 2026, with a further set tied to regulated products extending to August 2027. Building the AI inventory is a foundational CDO task, and organizations that delayed it are already behind the enforcement curve.
Key Takeaways
- GDPR is one of several major regimes. CCPA/CPRA (California), LGPD (Brazil), and India's DPDP Act all impose GDPR-like obligations with local twists, opt-out versus opt-in being a key difference in California.
- India's DPDP Act was passed in 2023, but its implementing rules were finalized in 2025 and enforcement is being phased in now.
- The EU AI Act entered into force in August 2024 and applies in stages: prohibited-practice bans from February 2025, GPAI model rules from August 2025, high-risk obligations from August 2026, and product-linked rules through August 2027.
- Build one compliance architecture, not one per regulation. A shared data inventory, consent record, DSAR workflow, vendor register, and PIA process serves every regime.
- The CDO owns the AI system inventory and risk classification. Without it, you cannot demonstrate AI Act compliance for high-risk systems.
What to do, from this lesson
These actions are compiled in the role's Playbook.
- Build a unified compliance architecture serving GDPR, CCPA, LGPD simultaneously
- Build an AI system inventory with risk classification before June 2026
Related articles
Recent articles from the blog that build on this lesson.
- DataGDPR beyond consent: why retention and minimization are the real compliance failuresMost organizations have built their GDPR programs around consent management and privacy notices, and declared victory. The harder obligations, data retention schedules and minimization, remain quietly ignored, and the 2026 wave of modern data tooling is making that gap more visible, not smaller.
- DataPrivacy-enhancing technologies in practice: a CDO playbookPrivacy-enhancing technologies have moved from research papers to production deployments, and CDOs who treat them as theoretical still carry unnecessary legal and competitive risk. This playbook walks through how to select, sequence, and embed PETs into your data architecture without stalling your analytics programme.
- DataPrivacy-enhancing technologies in practice: the hype is ahead of the implementationPrivacy-enhancing technologies have generated serious boardroom attention, and the underlying science is real. But the gap between pilot programs and production-grade deployment is wider than most CDOs are being told.