Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/CDO Track/Data governance & compliance/Privacy, ethics & regulation/CCPA, LGPD, AI Act: navigating the global regulatory patchwork
2/3+50 XP

Privacy, ethics & regulation

1GDPR in practice: the 10 mistakes CDOs make most often+502CCPA, LGPD, AI Act: navigating the global regulatory patchwork+50
3
Data ethics: beyond compliance, toward institutional trust
+45

CCPA, LGPD, AI Act: navigating the global regulatory patchwork

GDPR gets all the press. But if your organization operates globally, or plans to, you're facing a patchwork of privacy regulations that each require attention and, critically, a compliance architecture that can serve them all without rebuilding from scratch for each one.

The global regulatory landscape

CCPA / CPRA (California, USA)

The California Consumer Privacy Act (CCPA), enhanced by the California Privacy Rights Act (CPRA), gives California consumers rights similar to GDPR: right to know, right to delete, right to opt-out of sale. Key differences from GDPR:

  • Threshold-based: only applies to organizations meeting certain revenue or data volume thresholds
  • Opt-out model (not opt-in): consumers can opt out of data sale, but data processing is permitted by default
  • "Sale" of data is broadly defined, sharing data with third parties for commercial benefit may count as a sale
  • CPRA created a dedicated California Privacy Protection Agency (CPPA) with enforcement authority

Organizations that built GDPR compliance first have a significant head start on CCPA/CPRA, many of the same mechanisms apply, with adjustments.

LGPD (Brazil)

Lei Geral de Proteção de Dados (2020) is Brazil's GDPR equivalent. Nearly identical structure: six lawful bases, data subject rights, mandatory DPO for some organizations, breach notification within 72 hours. Key difference: enforcement is still maturing, the Brazilian National Data Protection Authority (ANPD) has been ramping up gradually.

India's DPDP Act (2023)

India's Digital Personal Data Protection Act came into force in 2023 and represents one of the largest jurisdictions outside the EU to implement GDPR-like protections. Applies to any organization processing digital personal data of Indian residents. Significant Data Fiduciary obligations, similar to data controller under GDPR.

The EU AI Act (2024)

The EU AI Act is the world's first comprehensive AI regulation. It takes a risk-tiered approach:

  • Prohibited AI (banned outright): Real-time biometric mass surveillance in public spaces, social scoring systems, AI that manipulates behavior exploiting vulnerabilities, AI that infers sensitive characteristics from biometrics.
  • High-risk AI: AI used in critical infrastructure, education, employment, essential services, law enforcement, migration. Requires conformity assessment, registration in EU database, human oversight mechanisms.
  • Limited risk: AI like chatbots, must disclose they are AI.
  • Minimal risk: No requirements.

Most enterprise AI falls in the "high-risk" or "limited risk" categories. Every CDO operating in the EU needs an AI Act compliance audit of their AI portfolio.

GDPR Compliance: Explain Like I'm Five with Data Privacy Expert

Watch on YouTube

Vérification des acquis

1. What is the most fundamental difference between the CCPA/CPRA consent model and the GDPR consent model?

2. An organization has already built a mature GDPR compliance program and now needs to comply with CCPA/CPRA and LGPD. What is the key strategic takeaway from the lesson?

3. Under the EU AI Act's risk-tiered approach, why does a chatbot fall into a different category than an AI system used for employment screening?

CHOIX MULTIPLES

4. Select ALL categories that the EU AI Act classifies as prohibited (banned outright) AI practices.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL statements that correctly describe LGPD and India's DPDP Act as presented in the lesson.

Sélectionnez toutes les réponses correctes.

Building a multi-regulation compliance architecture

The mistake: building separate compliance programs for each regulation. Separate GDPR team, separate CCPA team, separate AI Act team. This is expensive, creates inconsistencies, and doesn't scale as new regulations emerge.

The solution: a privacy compliance platform approach.

Core capabilities needed:

1. Data inventory and ROPA: Centralized record of all processing activities, applicable regulations, lawful bases, and retention periods. One record, multiple regulatory lenses.

2. Consent and preference management: A system of record for individual consent and preferences, queryable by regulation. Customer says "opt out" → this flows to CCPA compliance and GDPR processing simultaneously.

3. Data subject rights workflow: Automated intake, routing, and fulfillment of DSARs across all systems. Must handle access, erasure, portability. Must meet deadlines (30 days for GDPR, 45 for CCPA).

4. Vendor and DPA management: Track all data processors, DPA status, transfer mechanisms. Updated when vendors change.

5. Privacy impact assessment (DPIA/PIA): Integrated workflow that triggers when new projects or systems are proposed, routes to DPO review, documents decisions.

Tools in this space: OneTrust, TrustArc, Osano, DataGrail. These are not cheap, but the alternative (manual compliance management across multiple regulations) is more expensive and more risky.

The CDO's role in AI act compliance

The AI Act creates a new responsibility for CDOs: AI system inventory and risk classification. You need to know:

À faire, tiré de cette leçon

Ces actions sont compilées dans le plan d'action du rôle.

  • Build a unified compliance architecture serving GDPR, CCPA, LGPD simultaneously
  • Build an AI system inventory with risk classification before June 2026
Voir le plan d'action complet →

Précédent

GDPR in practice: the 10 mistakes CDOs make most often

Suivant

Data ethics: beyond compliance, toward institutional trust

What AI systems your organization uses (bought or built)
  • Which risk tier each falls into under the AI Act
  • What compliance obligations apply to high-risk systems
  • Who is accountable for compliance for each system
  • This doesn't exist in most organizations today. Building the AI inventory is a foundational CDO task that must happen before June 2026, when most AI Act obligations come into force.