The American answer: CCPA/CPRA and California’s ADMT rules
Lesson 6 of 6 in Privacy and Data Protection Law for AI: GDPR from Scratch.
The United States has no federal GDPR. What it has is a sectoral patchwork (HIPAA for health, GLBA for finance, FERPA for education, COPPA for children) plus a fast-growing family of state comprehensive privacy laws — and the template for those is California.
The CCPA (2018, effective 2020), amended by the CPRA ballot initiative (effective 2023), protects California consumers against covered businesses — for-profit entities doing business in California that clear at least one threshold: annual gross revenue above the inflation-adjusted $25 million mark, buying/selling/sharing personal information of 100,000+ consumers or households, or deriving 50%+ of revenue from selling or sharing personal information. The CPRA also created the CPPA — the first dedicated privacy regulator in the US — alongside Attorney General enforcement.
The philosophical difference from the GDPR matters more than any single provision. GDPR is a permission regime: processing is unlawful until a lawful basis legitimises it. CCPA is a transparency-and-opt-out regime: businesses may process, but must disclose, honour rights, and stop selling or sharing on request. Consumers get rights to know/access, delete, correct (added by CPRA), opt out of sale/share, and limit use of sensitive personal information; businesses must honour universal opt-out signals like Global Privacy Control and must not discriminate against rights-exercisers. The private right of action stays narrow — data breaches only — with civil penalties otherwise: up to $2,500 per violation, $7,500 if intentional or involving minors, per consumer per incident, which scales brutally for AI systems touching millions of records.
| GDPR (EU) | CCPA/CPRA (California) | |
|---|---|---|
Model | Permission regime — processing prohibited without a lawful basis; data protection as a fundamental right | Opt-out regime — processing allowed with notice; consumer-protection framing |
Who is covered | Any controller/processor processing data of people in the EU (plus extraterritorial reach under Art 3) | For-profit businesses over thresholds (~$25M revenue, 100k consumers, or 50% revenue from selling/sharing) |
Key roles | Controller / processor / joint controllers | Business / service provider / contractor / third party |
Lawful basis required? | Yes — one of six under Art 6; Art 9 conditions for special categories | No — notice at collection instead; consent needed mainly for minors and some sensitive uses |
Sensitive data | Art 9 prohibition unless a specific condition applies | Right to limit use of sensitive personal information; opt-in for minors |
Automated decisions | Art 22 prohibition-with-exceptions + safeguards + logic transparency | CPPA ADMT regulations: pre-use notice, opt-out (with exceptions), access/explanation for significant decisions |
Individual rights | Access, rectification, erasure, restriction, portability, objection | Know/access, delete, correct, opt out of sale/share, limit sensitive PI, non-discrimination |
Regulator & penalties | National DPAs; up to €20M or 4% of global turnover | CPPA + Attorney General; $2,500/$7,500 per violation; private action for breaches only |
The ADMT regulations are California’s Article 22 moment. Finalised by the CPPA in 2025 after a bruising multi-year rulemaking (early drafts covering behavioural advertising and "AI" broadly were cut back under business and gubernatorial pressure), the regulations attach duties to automated decision-making technology — technology that processes personal information and replaces or substantially replaces human decision-making — when used for significant decisions: financial or lending services, housing, education, employment, and healthcare.
Covered businesses owe consumers a pre-use notice, a right to opt out (with exceptions, including where a human-appeal route is offered), and a right to access information about how the ADMT reached its decision. Companion rules require risk assessments for high-risk processing — including training ADMT and certain profiling — and cybersecurity audits, phasing in over several years. Meanwhile Colorado, Connecticut, Virginia and most other state privacy laws grant an opt-out of profiling in furtherance of significant decisions, so the pattern generalises beyond California.
Tool: Which Rules Apply? — Which privacy and AI rules apply to your system? Walk a real deployment through the applicability wizard.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.