Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/CDO Track/Data governance & compliance/Privacy, ethics & regulation/CCPA, LGPD, AI Act: navigating the global regulatory patchwork
2/3+50 XP

Privacy, ethics & regulation

1GDPR in practice: the 10 mistakes CDOs make most often+502CCPA, LGPD, AI Act: navigating the global regulatory patchwork+503Data ethics: beyond compliance, toward institutional trust+45

CCPA, LGPD, AI Act: navigating the global regulatory patchwork

GDPR gets all the press. But if your organization operates globally, or plans to, you're facing a patchwork of privacy regulations that each require attention and, critically, a compliance architecture that can serve them all without rebuilding from scratch for each one.

The global regulatory landscape

CCPA / CPRA (California, USA)

The California Consumer Privacy Act (CCPA), enhanced by the California Privacy Rights Act (CPRA), gives California consumers rights similar to GDPR: right to know, right to delete, right to opt-out of sale. Key differences from GDPR:

  • Threshold-based: only applies to organizations meeting certain revenue or data volume thresholds
  • Opt-out model (not opt-in): consumers can opt out of data sale, but data processing is permitted by default
  • "Sale" of data is broadly defined, sharing data with third parties for commercial benefit may count as a sale
  • CPRA created a dedicated California Privacy Protection Agency (CPPA) with enforcement authority

Organizations that built GDPR compliance first have a significant head start on CCPA/CPRA, many of the same mechanisms apply, with adjustments.

LGPD (Brazil)

Lei Geral de Proteção de Dados (2020) is Brazil's GDPR equivalent. Nearly identical structure: six lawful bases, data subject rights, mandatory DPO for some organizations, breach notification within 72 hours. Key difference: enforcement is still maturing, the Brazilian National Data Protection Authority (ANPD) has been ramping up gradually.

India's DPDP Act (2023)

India's Digital Personal Data Protection Act came into force in 2023 and represents one of the largest jurisdictions outside the EU to implement GDPR-like protections. Applies to any organization processing digital personal data of Indian residents. Significant Data Fiduciary obligations, similar to data controller under GDPR.

The EU AI Act (2024)

The EU AI Act is the world's first comprehensive AI regulation. It takes a risk-tiered approach:

  • Prohibited AI (banned outright): Real-time biometric mass surveillance in public spaces, social scoring systems, AI that manipulates behavior exploiting vulnerabilities, AI that infers sensitive characteristics from biometrics.
  • High-risk AI: AI used in critical infrastructure, education, employment, essential services, law enforcement, migration. Requires conformity assessment, registration in EU database, human oversight mechanisms.
  • Limited risk: AI like chatbots, must disclose they are AI.
  • Minimal risk: No requirements.

Most enterprise AI falls in the "high-risk" or "limited risk" categories. Every CDO operating in the EU needs an AI Act compliance audit of their AI portfolio.

GDPR Compliance: Explain Like I'm Five with Data Privacy Expert

Watch on YouTube

Knowledge check

1. What is the most fundamental difference between the CCPA/CPRA consent model and the GDPR consent model?

2. An organization has already built a mature GDPR compliance program and now needs to comply with CCPA/CPRA and LGPD. What is the key strategic takeaway from the lesson?

3. Under the EU AI Act's risk-tiered approach, why does a chatbot fall into a different category than an AI system used for employment screening?

MULTIPLE CHOICE

4. Select ALL categories that the EU AI Act classifies as prohibited (banned outright) AI practices.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL statements that correctly describe LGPD and India's DPDP Act as presented in the lesson.

Select all the correct answers.

Building a multi-regulation compliance architecture

The mistake: building separate compliance programs for each regulation. Separate GDPR team, separate CCPA team, separate AI Act team. This is expensive, creates inconsistencies, and doesn't scale as new regulations emerge.

The solution: a privacy compliance platform approach.

Core capabilities needed:

1. Data inventory and ROPA: Centralized record of all processing activities, applicable regulations, lawful bases, and retention periods. One record, multiple regulatory lenses.

2. Consent and preference management: A system of record for individual consent and preferences, queryable by regulation. Customer says "opt out" → this flows to CCPA compliance and GDPR processing simultaneously.

3. Data subject rights workflow: Automated intake, routing, and fulfillment of DSARs across all systems. Must handle access, erasure, portability. Must meet deadlines (30 days for GDPR, 45 for CCPA).

4. Vendor and DPA management: Track all data processors, DPA status, transfer mechanisms. Updated when vendors change.

5. Privacy impact assessment (DPIA/PIA): Integrated workflow that triggers when new projects or systems are proposed, routes to DPO review, documents decisions.

Tools in this space: OneTrust, TrustArc, Osano, DataGrail. These are not cheap, but the alternative (manual compliance management across multiple regulations) is more expensive and more risky.

The CDO's role in AI act compliance

The AI Act creates a new responsibility for CDOs: AI system inventory and risk classification. You need to know:

  • What AI systems your organization uses (bought or built)
  • Which risk tier each falls into under the AI Act
  • What compliance obligations apply to high-risk systems
  • Who is accountable for compliance for each system

This doesn't exist in most organizations today. Building the AI inventory is a foundational CDO task that must happen before June 2026, when most AI Act obligations come into force.

What to do, from this lesson

These actions are compiled in the role's Playbook.

  • Build a unified compliance architecture serving GDPR, CCPA, LGPD simultaneously
  • Build an AI system inventory with risk classification before June 2026
See the full action playbook →

Previous

GDPR in practice: the 10 mistakes CDOs make most often

Next

Data ethics: beyond compliance, toward institutional trust