HIPAA, CCPA/CPRA, and GDPR side by side — the numbers people forget under time pressure. Deadlines only; each law has substantive requirements well beyond what's on this card.
| HIPAA | CCPA / CPRA | GDPR | |
|---|---|---|---|
| Scope | Covered entities & business associates handling PHI | For-profit businesses meeting revenue/data-volume thresholds, doing business in California | Any org processing EU/EEA residents' personal data, regardless of where the org is based |
| Protected data | Protected Health Information (PHI) | "Personal information" — broad, includes inferences | "Personal data" — broad, includes online identifiers |
| HIPAA | CCPA / CPRA | GDPR | |
|---|---|---|---|
| Regulator | HHS: ≤60 days from discovery if ≥500 affected; within 60 days of year-end if <500 | Not a CCPA-specific deadline — CA's general breach law (Civ. Code §1798.82) requires "the most expedient time possible, without unreasonable delay" | Supervisory authority: 72 hours from awareness, if risk to rights/freedoms |
| Affected people | ≤60 days from discovery, without unreasonable delay | Same "most expedient time" standard as above — commonly treated as 30–45 days in practice | Without undue delay, only when the breach is high-risk to the individual |
| HIPAA | CCPA / CPRA | GDPR | |
|---|---|---|---|
| Deadline | 30 days for a records access request (§164.524) — not the same clock as breach notification | 45 days, extendable once by another 45 (90 max) with notice to the consumer; acknowledge receipt within 10 business days | 1 month, extendable by 2 further months for complex requests, with notice |