Movatterモバイル変換


[0]ホーム

URL:


  • Free Resources
  • Industries
    Solutions for industries:
    • Consultants
    • IT & SaaS companies
    • Critical infrastructure
    • Manufacturing
    • Transportation & distribution
    • Education
    • Telecommunications
    • Banking & finance
    • Government
    • Health organizations
    • Medical device
    • Aerospace
    • Automotive
    • Laboratories
    1. Implementation, maintenance, training, and knowledge products for consultancies.

    2. Conformio for Consultants

      Handle multiple ISO 27001 projects by automating repetitive tasks during ISMS implementation.

    3. Consultant Toolkits

      All required policies, procedures, and forms to implement various standards and regulations for your clients.

    4. Company Training Academy for Consultants

      Grow your business by organizing cybersecurity and compliance training for your clients under your own brand using Advisera’s learning management system platform.

    5. Courses for Building and Growing a Consultancy

      Accredited Lead Auditor and Lead Implementer courses for ISO standards and DORA, and an advanced course to help consultants grow their business.

    6. Experta ISO Knowledge Base

      Get instant answers to any questions related to ISO 27001 (ISMS), ISO 9001 (QMS), and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    7. Consultant Directory

      Find new clients, potential partners, and collaborators and meet a community of like-minded professionals locally and globally.

    1. IT & SaaS companies

      Implementation, maintenance, training, and knowledge products for the IT industry.

    2. Conformio ISO 27001 Software

      Automate your ISMS implementation and maintenance with the Risk Register, Statement of Applicability, and wizards for all required documents.

    3. ISO 27001, 22301, 20000, GDPR, NIS 2 and DORA Documentation Toolkits

      Documentation to comply with ISO 27001 (cybersecurity), ISO 22301 (business continuity), ISO 20000 (IT service management), GDPR (privacy), NIS 2 (critical infrastructure cybersecurity), and DORA (cybersecurity for financial sector).

    4. NIS 2, DORA, ISO 27001, GDPR, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    5. ISO 27001, DORA and GDPR Online Courses

      Accredited courses for individuals and security professionals who want the highest-quality training and certification.

    6. Experta ISO 27001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 and the ISMS using Advisera’s proprietary AI-powered knowledge base.

    1. Critical infrastructure

      Compliance, training, and knowledge products for essential and important organizations.

    2. NIS 2, GDPR, ISO 27001, and ISO 22301 Documentation Toolkits

      Documentation to comply with NIS 2 (cybersecurity), GDPR (privacy), ISO 27001 (cybersecurity), and ISO 22301 (business continuity).

    3. NIS 2, GDPR, and Cybersecurity Training & Awareness

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 27001 and GDPR Online Courses

      Accredited courses for individuals and security professionals who want the highest-quality training and certification.

    5. Experta ISO 27001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 and the ISMS using Advisera’s proprietary AI-powered knowledge base.

    1. Manufacturing

      Implementation, training, and knowledge products for manufacturing companies.

    2. ISO 9001, 14001, 45001, and NIS 2 Documentation Toolkits

      Documentation to comply with ISO 9001 (quality), ISO 14001 (environmental), and ISO 45001 (health & safety), and NIS 2 (critical infrastructure cybersecurity).

    3. NIS 2 and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 9001, 14001, and 45001 Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 9001 and 14001 Knowledge Base

      Get instant answers to any questions related to ISO 9001 (QMS) and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Transportation & distribution

      Implementation, training, and knowledge products for transportation & distribution companies.

    2. ISO 9001, 14001, 45001, and NIS 2 Documentation Toolkits

      Documentation to comply with ISO 9001 (quality), ISO 14001 (environmental), and ISO 45001 (health & safety), and NIS 2 (critical infrastructure cybersecurity).

    3. NIS 2 and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 9001, 14001, and 45001 Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 9001 and 14001 Knowledge Base

      Get instant answers to any questions related to ISO 9001 (QMS) and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Education

      Implementation, training, and knowledge products for schools, universities, and other educational organizations.

    2. ISO 27001, 9001, and GDPR Documentation Toolkits

      Documentation to comply with ISO 27001 (cybersecurity), ISO 9001 (quality), and GDPR (privacy).

    3. ISO 27001, GDPR, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 27001, 9001, and GDPR Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 27001 and 9001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 (ISMS) and ISO 9001 (QMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Telecommunications

      Implementation, maintenance, training, and knowledge products for telecoms.

    2. Conformio ISO 27001 Software

      Automate your ISMS implementation and maintenance with the Risk Register, Statement of Applicability, and wizards for all required documents.

    3. ISO 27001, 22301, 20000, GDPR, and NIS 2 Documentation Toolkits

      Documentation to comply with ISO 27001 (cybersecurity), ISO 22301 (business continuity), ISO 20000 (IT service management), GDPR (privacy), and NIS 2 (critical infrastructure cybersecurity).

    4. NIS 2, GDPR, ISO 27001, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    5. ISO 27001 and GDPR Online Courses

      Accredited courses for individuals and security professionals who want the highest-quality training and certification.

    6. Experta ISO 27001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 and the ISMS using Advisera’s proprietary AI-powered knowledge base.

    1. Banking & finance

      Implementation, maintenance, training, and knowledge products for banks, insurance companies, and other financial organizations.

    2. Conformio ISO 27001 Software

      Automate your ISMS implementation and maintenance with the Risk Register, Statement of Applicability, and wizards for all required documents.

    3. DORA, ISO 27001, 22301 and GDPR Documentation Toolkits

      Documentation to comply with DORA (cybersecurity for financial sector), ISO 27001 (cybersecurity), ISO 22301 (business continuity), and GDPR (privacy).

    4. DORA, NIS 2, GDPR, ISO 27001, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    5. DORA, ISO 27001 and GDPR Online Courses

      Accredited courses for individuals and security professionals who want the highest-quality training and certification.

    6. Experta ISO 27001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 and the ISMS using Advisera’s proprietary AI-powered knowledge base.

    1. Government

      Implementation, training, and knowledge products for local, regional, and national government entities.

    2. ISO 27001, 9001, GDPR, and NIS 2 Documentation Toolkits

      Documentation to comply with ISO 27001 (cybersecurity), ISO 9001 (quality), GDPR (privacy), and NIS 2 (critical infrastructure cybersecurity).

    3. NIS 2, ISO 27001, GDPR, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 27001, 9001, and GDPR Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 27001 and 9001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 (ISMS) and ISO 9001 (QMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Health organizations

      Implementation, training, and knowledge products for hospitals and other health organizations.

    2. ISO 27001, 9001, 14001, 45001, NIS 2, and GDPR Documentation Toolkits

      Documentation to comply with ISO 27001 (cybersecurity), ISO 9001 (quality), ISO 14001 (environmental), ISO 45001 (health & safety), NIS 2 (critical infrastructure cybersecurity) and GDPR (privacy).

    3. NIS 2, GDPR, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 27001, 9001, 14001, 45001, and GDPR Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 27001, 9001, and 14001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 (ISMS), ISO 9001 (QMS), and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Medical device

      Implementation, training, and knowledge products for the medical device industry.

    2. ISO 13485, 27001, 9001, 14001, 45001, NIS 2, and GDPR Documentation Toolkits

      Documentation to comply with MDR and ISO 13485 (medical device), ISO 27001 (cybersecurity), ISO 9001 (quality), ISO 14001 (environmental), ISO 45001 (health & safety), NIS 2 (critical infrastructure cybersecurity) and GDPR (privacy).

    3. NIS 2, ISO 27001, GDPR, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 13485, 27001, 9001, 14001, 45001, and GDPR Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 27001, 9001, and 14001 Knowledge Base

      Get instant answers to any questions related to ISO 27001 (ISMS), ISO 9001 (QMS), and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Aerospace

      Implementation, training, and knowledge products for the aerospace industry.

    2. AS9100, ISO 9001, 14001, 45001, and NIS 2 Documentation Toolkits

      Documentation to comply with AS9100 (aerospace), ISO 9001 (quality), ISO 14001 (environmental), and ISO 45001 (health & safety), and NIS 2 (critical infrastructure cybersecurity).

    3. NIS 2 and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 9001, 14001, and 45001 Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 9001 and 14001 Knowledge Base

      Get instant answers to any questions related to ISO 9001 (QMS) and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Automotive

      Implementation, training, and knowledge products for the automotive industry.

    2. IATF 16949, ISO 9001, 14001, 45001, and NIS 2 Documentation Toolkits

      Documentation to comply with IATF 16949 (automotive), ISO 9001 (quality), ISO 14001 (environmental), and ISO 45001 (health & safety), and NIS 2 (critical infrastructure cybersecurity).

    3. NIS 2, ISO 27001, and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 9001, 14001, and 45001 Online Courses

      Accredited courses for individuals and professionals who want the highest-quality training and certification.

    5. Experta ISO 9001 and 14001 Knowledge Base

      Get instant answers to any questions related to ISO 9001 (QMS) and ISO 14001 (EMS) using Advisera’s proprietary AI-powered knowledge base.

    1. Laboratories

      Implementation, training, and knowledge products for laboratories.

    2. ISO 17025, 9001, and NIS 2 Documentation Toolkits

      Documentation to comply with ISO 17025 (testing and calibration laboratories), ISO 9001 (quality), and NIS 2 (critical infrastructure cybersecurity).

    3. NIS 2 and Security Awareness Training

      Company-wide cybersecurity awareness program for all employees, to decrease incidents and support a successful cybersecurity program.

    4. ISO 9001 Online Courses

      Accredited courses for individuals and quality professionals who want the highest-quality training and certification.

    5. Experta ISO 9001 Knowledge Base

      Get instant answers to any questions related to ISO 9001 and the QMS using Advisera’s proprietary AI-powered knowledge base.

  • About Us
  • About Us
  • Contact Us
    1. Home
    2. Resources
    3. The differences between the California Consumer Privacy Act and the GDPR

    The differences between the California Consumer Privacy Act and the GDPR

    Article byAdvisera Francesca LucariniFrancesca Lucarini4 min read

    Almost two years after theGDPR came into force, a new data privacy regulation has come from the land where some of the world’s leaders in the development of new technologies were born and have their current main establishments. We are talking about the California Consumer Privacy Act (CCPA), the comprehensive privacy law enacted in the state of the California in June 2018 and which became effective on January 1, 2020.

    Known as the American counterpart to the European Union General Data Protection Regulation (GDPR), the CCPA grants people who live in California rights regarding the use of their personal information and establishes requirements for companies that conduct business inside the state of California. The CCPA and the GDPR have similarities, such as sharing fundamental concepts like the right to data deletion and data portability and the same rationale, to give people control over how their personal data are used online. However, there are some differences that will be useful to highlight.

    Here’s a summary of the differences:

    The differences between the California Consumer Privacy Act and the GDPR

    Let’s explain these things in more detail…

    Data subject vs. consumer

    While both of these laws refer to any natural person identifiable by a set of specific terms, such as name and so on, under the California Consumer Privacy Act the consumer is any natural person defined as a California resident.

    Definition of personal data

    Although both the GDPR and CCPA refer to this term as any information which can identify a natural person, the CCPA is a little bit more specific in saying that personal data could be also commercial information such as those relating to “personal property, services and products purchased.” That is, a consumer could be also a customer of a household.

    Territorial scope

    Differently from the GDPR, the CCPA only regulates companies doing business in the state of California, and satisfying one or more of these thresholds:

    1. They have annual gross revenues of $ 25,000,000.
    2. They process the personal information of 50,000 or more consumers, households, or devices annually.
    3. They derive 50% or more of their annual revenue from the processing of Californians’ personal information.

    Read more here:Is the GDPR applicable to our company?

    User’s rights

    In establishing the user’s rights, both the General Data Protection Regulation and the California Consumer Privacy Act establish:

    • The right of the data subject/consumer to know the categories of personal information collected by the company and their use purposes, including any third parties with which it shares this information (article 15 of the GDPR, right to access).
    • The right of the data subject/consumer to obtain the deletion of personal information regarding himself or herself. Both laws establish exceptions to this right (article 17 of the GDPR, right to erasure).
    • The right of the data subject/consumer to have data concerning him or her in a structured, machine-readable/readily usable format as to enable the transmission of the same data to another controller without hindrance (article 20 of the GDPR, right to data portability).

    Regarding differences, the California Consumer Privacy Act establishes the right to opt-out, which, from a certain point of view, could recall the right to object established by the GDPR inarticle 21.

    According to the CCPA, Californians are given the right to opt-out of the selling of their personal information to third parties. “To sell” here refers to any kind of processing of a consumer’s personal information “for monetary or other valuable consideration.”

    Read also:8 data subject rights according to GDPR.

    Penalties

    Both the GDPR and the CCPA establish penalties for non-compliance, whether as fines resulting in private right of action or as fines imposed on controllers. In the first case, both laws establish that an individual can exercise a right of action because of a security breach or a violation that occurs during the processing of personal data. However, the CCPA’s right seems to be more restricted than the GDPR’s, granting every company a 30-day period to cure the violation, where feasible, in order for the private civil action to be prevented. Regarding administrative fines, a different approach in calculation of fines is clear and has been described in the table above.

    Privacy as a business achievement?

    More could be said about points of contact between the GDPR and the CCPA. Surely, more could be said about the sobering prospects opening for the companies operating globally: each one of them is required to revise their data protection policies in order to be compliant with laws holding them accountable if they do not protect their clients’ data, even outside the European Union. Maybe it’s time for companies to start considering data privacy a business achievement rather than a mere requirement to be compliant with.

    Download a free preview of theEU GDPR Premium Documentation Toolkitto see the structure for each document mentioned above.

    TagsArticlesEU GDPRRevisions & Related

    EU GDPR Premium Documentation Toolkit

    Step-by-step GDPR compliance for smaller companies
    Find out more
    EU GDPR
    Premium Documentation Toolkit

    Step-by-step GDPR compliance for smaller companies

    Advisera Francesca Lucarini

    Francesca Lucarini

    Francesca Lucarini is a cybersecurity advisor, ISO 27001 qualified auditor, and expert in communicating GDPR and information security themes, as well as the suggestion of tools to help people and companies increase their awareness of the risks that can occur with the use of technology.
    Read more articles by Francesca Lucarini

    Related Products

    Upcoming Free Webinar

    Advisera Dejan Kosutic
    PresenterDejan Kosutic
    How to Get Ongoing Consultant Revenue From Clients
    Wednesday – November 5, 2025
    Register Now

    Related Articles

    How to comply with EU GDPR, UK GDPR and Data Protection Actby Alessandra Nistico
    How does GDPR affect digital marketing?by David Cauchi
    How to make remote working compliant with the GDPRby Francesca Lucarini
    You have successfully subscribed! You'll receive the next newsletter in a week or two.
    Please enter your email address to subscribe to our newsletter like 20,000+ others

    You may unsubscribe at any time. For more information, please see ourprivacy notice.


    [8]ページ先頭

    ©2009-2025 Movatter.jp