$ cat blog/privacy-infomation
Back to Blog
Compliance••12 min read

Understanding GDPR, CCPA, and Core Data Privacy Principles for Modern Businesses

What actually counts as 'personal data' under GDPR and CCPA? Real examples — from the ad that follows you around to what makes location data 'sensitive' — plus the key terms and rights, in plain language.

Understanding GDPR, CCPA, and Core Data Privacy Principles for Modern Businesses

Sign up for a newsletter, buy something online, or open an app, and your data moves — collected, stored, shared with whoever that company works with. Most people have a vague sense this happens. Few could tell you exactly what counts as "their data" or what a company is actually allowed to do with it.

This post introduces the key areas of data privacy, focusing on leading regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We’ll also break down essential privacy principles and terminology so businesses and individuals alike can better understand how data should be handled—and why it matters.


What Is Data Privacy?

Data privacy refers to the right of individuals to control how their personal information is collected, used, and shared. It also encompasses the obligations of organizations to handle that data responsibly.

"Personal data" covers a lot more than people assume — the section below walks through what that actually means with real examples, not just a legal definition.


What Actually Counts as "Personal Data"? (With Examples)

This is the part that trips people up. "Personal data" sounds like it means your name and maybe your Social Security number. Under both GDPR and CCPA, it means almost anything that identifies you, describes you, or could reasonably be traced back to you — which is a lot broader than most people picture. A few concrete examples make this easier to grasp than the legal language does on its own.

Everyday personal data — things most businesses collect without a second thought:

  • Your name, email address, and mailing address
  • Your phone number
  • Your IP address or a cookie ID. Example: the shoes you looked at once that now follow you around the internet in ads — that's possible because your browser got assigned an identifier, and that identifier counts as personal data.
  • Your purchase history. Example: a grocery store loyalty card building a three-year record of everything you've bought is personal data, even though no single purchase looks sensitive by itself.
  • Your employment and education history
  • Inferences a company draws about you. Example: if a streaming service flags you as "likely to cancel" based on how often you log in, that label about you is personal data too — not just the login count it was built from.

Sensitive personal data — both laws call these out for extra protection, because getting them wrong causes real harm, not just annoyance:

  • Health information. Example: a record showing you see a therapist — not just a general insurance claim — falls here. GDPR calls this a "special category" (Article 9) and bans processing it by default unless a specific exception applies.
  • Biometric data used to identify someone. Example: the fingerprint or face scan that unlocks your phone, if a company stores it to verify who you are.
  • Precise geolocation. Example: a rideshare app's GPS trail of exactly where you've been is sensitive under California's CPRA (Civ. Code §1798.140(ae)) once it's accurate to within about 1,850 feet — a store just knowing "this customer is somewhere in Maine" from a billing zip code is not.
  • Racial or ethnic origin, religious beliefs, and union membership. Example: responses to an employer's DEI survey, or an HR record noting someone's union status.
  • Government ID numbers and login credentials. Example: a Social Security number, a driver's license number, or the password to your email account.
  • Genetic data. Example: the raw data file a consumer DNA testing kit generates about you.

What's usually not covered: information that's already lawfully public (a business's listed phone number, a public property record) and data that's been properly de-identified or aggregated so it can't be traced back to a specific person. Both laws are strict about what actually qualifies as de-identified — removing someone's name isn't enough if they could still be picked out from what's left.

Why the split matters: a company handling everyday personal data generally has to be transparent about it and give people some control. A company handling the sensitive categories faces a higher bar — GDPR bans processing special categories by default unless a specific legal exception applies, and under CPRA, California consumers get a standalone right to limit how a business uses their sensitive personal information (§1798.121), separate from the general right to opt out of a sale.

For the full side-by-side — how GDPR's and CCPA's category lists compare, with the exact statute or article cited for each — see Anchor's GDPR/CCPA Consent & Data Protection Field Reference.


Overview of Key Privacy Frameworks

GDPR (General Data Protection Regulation) – European Union

  • Applies to: Any organization that processes personal data of individuals located in the EU, regardless of where the organization is based.
  • Key Rights for Individuals:
    • Right to Access: Individuals can request a copy of the personal data an organization holds about them.
      Example: A user can email a company asking to see all stored data related to their account.
    • Right to Rectification and Erasure: Individuals can request corrections to inaccurate data or ask for data to be deleted.
    • Right to Object: Individuals can object to how their data is being used, such as for marketing.
    • Right to Data Portability: Individuals can request their data in a structured format to take it elsewhere.

CCPA/CPRA (California Consumer Privacy Act, as amended by the California Privacy Rights Act) – United States (California)

  • Applies to: For-profit businesses that do business in California and meet specific thresholds related to revenue, data volume, or data sales.
  • Key Rights for Individuals:
    • Right to Know: Consumers can ask what categories and specific pieces of personal information a business collects and why.
    • Right to Delete: Consumers can request that a business delete the personal data it has collected about them.
    • Right to Opt Out of Sale: Consumers can instruct businesses not to sell their personal data.
      Example: A user can click a “Do Not Sell My Info” link on a website to prevent the sale of their information to advertising partners.
    • Right to Non-Discrimination: Consumers must not be penalized for exercising their privacy rights.

Global Privacy Laws: A Growing Landscape

While GDPR and CCPA are among the most well-known privacy frameworks, many other jurisdictions have implemented or are drafting their own regulations. These include Brazil’s LGPD, Canada’s PIPEDA and upcoming CPPA, India’s DPDP Act, Japan’s APPI, and others. While specifics vary, most modern privacy laws are built around similar principles: transparency, accountability, and individual rights.


Core Privacy Concepts Explained

Personally Identifiable Information (PII)

Any information that can identify an individual, either on its own or when combined with other data. This includes names, email addresses, government IDs, login credentials, and device identifiers.

Data Minimization

Organizations should only collect the data necessary to fulfill a specific purpose. Collecting extra data "just in case" increases risk and may violate compliance standards.

Data Retention

Personal data should not be retained longer than necessary. Organizations must define and document data retention schedules and ensure that data is deleted or anonymized when no longer needed.

Data Processors and Data Controllers

Understanding whether your organization is acting as a data controller or a data processor is essential under privacy laws like GDPR:

  • Data Controller: The entity that determines the purposes and means of processing personal data.
  • Data Processor: The entity that processes personal data on behalf of the controller.

Example for a SaaS Company Using Cloud Infrastructure:

Suppose your company offers a SaaS marketing platform that collects customer data to provide analytics.

  • Your company is the controller of the end-user data collected via your product. You determine what data is collected, how it’s used, and why.
  • If you use AWS, Google Cloud Platform (GCP), or Microsoft Azure to host your infrastructure, those providers are processors. They process the data under your instructions and do not control what the data is or how it’s used.

Even though these cloud providers offer strong security and compliance tooling, your organization remains responsible for:

  • Ensuring appropriate data processing agreements (DPAs) are in place with each provider.
  • Understanding where the data is stored and whether it crosses international borders.
  • Configuring services securely to prevent unauthorized access or breaches.

Additionally, if your SaaS platform integrates with other third-party tools (e.g., CRMs, email marketing services), each of those tools may also be considered processors, and similar diligence must be applied.

What About Sub-Processors?

It doesn't stop at one layer. The CRM your SaaS platform integrates with might host its own infrastructure on a cloud provider, and that cloud provider might use a subcontractor for backup storage — each link past the first processor is a sub-processor: a processor that another processor brought in to help handle the data, rather than one you contracted with directly.

GDPR doesn't let this happen silently. Under Article 28(2), a processor can't bring in a sub-processor without your prior authorization — either a specific sign-off for that one vendor, or a general authorization where they have to tell you about new sub-processors and give you a chance to object before the change takes effect. Under Article 28(4), whoever brings in the sub-processor has to bind them, by contract, to the same data protection obligations your DPA imposed — not a watered-down version. And if that sub-processor causes a breach, your processor stays fully liable to you. "It was our vendor's fault" isn't a defense.

Example: your email marketing platform (your processor) uses a transactional email API (their sub-processor) to actually send the messages. If that API provider has a breach, your email platform is still on the hook to you — they can't point at their vendor and walk away.

This is also what a DPA is actually supposed to pin down, not just something you sign and file away. GDPR Article 28(3) requires the contract to address: processing only on your documented instructions, confidentiality for anyone handling the data, the security measures required under Article 32, the sub-processor authorization terms above, help responding to data subject requests and breaches, what happens to the data when the contract ends (deleted or returned), and your right to audit. A one-line "we take security seriously" clause doesn't meet that bar.

CCPA/CPRA runs a parallel version of the same idea. Under Civil Code §1798.100(d), a business's contract with a service provider or contractor has to limit what they can do with the data, require them to follow CCPA, give the business the right to check on them, and require them to speak up if they can no longer meet those obligations. The CCPA regulations (11 CCR §7051) go further: if that service provider or contractor subcontracts the work again, the subcontract has to carry the same restrictions forward. Same flow-down logic as GDPR's sub-processor rule, different label.

Key Takeaway: If your business collects and decides how personal data is used—even if it's hosted in the cloud—you are a controller and must comply with relevant privacy laws. Your cloud provider acts as a processor, and their role is to support your instructions under strict legal and contractual safeguards. That chain of responsibility doesn't break just because they bring in help of their own.

Consent must be freely given, specific, informed, and unambiguous. Individuals should have a genuine choice and the ability to withdraw consent easily.

Security and Confidentiality

Organizations must implement appropriate technical and organizational measures to protect data. This includes encryption, access controls, incident response procedures, and regular audits.

Cross-Border Data Transfers

When personal data is transferred across international borders (e.g., from the EU to the U.S.), it must be protected in line with legal frameworks. Mechanisms such as Standard Contractual Clauses (SCCs) or adequacy decisions may apply.


Why Privacy Matters

Protecting personal data is more than just a compliance requirement—it’s a trust-building practice. Privacy safeguards:

  • Reduce the risk of data breaches and misuse
  • Enhance customer loyalty and brand reputation
  • Align your business with global standards and expectations
  • Empower individuals to maintain control over their personal information

What You Can Do to Stay Privacy-Forward

Whether you're an individual or part of a growing business:

  • Understand your role in the data ecosystem (controller or processor)
  • Implement clear privacy notices and consent mechanisms
  • Review your third-party vendors for compliance
  • Train employees on privacy principles
  • Conduct regular audits and data mapping exercises
  • Respond to privacy rights requests in a timely and transparent way

Conclusion

Data privacy is no longer optional—it’s a foundational element of operating in a digital economy. Laws like GDPR and CCPA are shaping the way organizations collect, use, and protect personal information. Whether you're a consumer curious about your rights or a business leader building responsible data practices, understanding these key concepts is essential.

With privacy expectations and regulations evolving worldwide, now is the time to build a privacy-conscious culture that respects individuals and strengthens your organization from the inside out.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch