GDPR, CCPA, DPDP: The Global Privacy Landscape in 2026

From Europe to California to India, privacy regulations now govern how websites collect, store, and transfer personal data. What each law requires and who it applies to.

GDPR, CCPA, DPDP: The Global Privacy Landscape in 2026

In May 2018, a regulation went into force across the European Union that required every company handling European personal data to overhaul how they stored, processed, and transferred it. The GDPR was not the first privacy law, but it was the first with teeth large enough to make multinational corporations nervous. The maximum fine was either 4% of global annual revenue or 20 million euros, whichever was higher.

In the years since, the rest of the world has been catching up. California, Brazil, India, South Africa, and dozens of other jurisdictions have passed their own frameworks. Understanding which rules apply to you, and what they actually require, is no longer optional for anyone running a website or a business that collects data.

GDPR: the European standard

The General Data Protection Regulation applies to any organization that processes the personal data of individuals in the EU, regardless of where the organization is based. A company in Chicago that sells to European customers must comply. A startup in Singapore with EU users must comply.

The GDPR defines personal data broadly: any information that can identify a living individual, directly or indirectly. This includes names and email addresses, obviously, but also IP addresses (the Court of Justice of the EU confirmed this in the Breyer case in 2016), cookie identifiers, device fingerprints, and location data. If you collect IP addresses and log them, you are processing personal data.

The regulation requires a lawful basis for processing. The most commonly cited basis for commercial activity is legitimate interests, but the regulation requires a genuine balancing test. Consent is another basis but must be freely given, specific, informed, and unambiguous. Pre-ticked checkboxes do not count, and neither does consent buried in terms of service.

The largest fine under GDPR to date was handed to Meta in May 2023: 1.2 billion euros from the Irish Data Protection Commission for transferring European user data to the United States without adequate safeguards. The Schrems II decision in 2020 had invalidated the previous Privacy Shield framework, and Meta continued operating under standard contractual clauses that regulators deemed insufficient.

CCPA: California sets the US standard

The California Consumer Privacy Act came into force in January 2020 and was substantially amended by the California Privacy Rights Act (CPRA), which took effect in January 2023. Together they form the strictest privacy framework in the United States.

Unlike the GDPR's universal scope, CCPA applies to for-profit businesses that meet specific thresholds: annual gross revenue above $25 million, data on 100,000 or more California consumers annually (lowered from 50,000 under the original CCPA), or more than 50% of annual revenue from selling personal data. A small business with minimal California traffic is not covered. A large e-commerce company almost certainly is.

CCPA gives California residents specific rights: to know what personal information a business has collected, to delete it, to opt out of its sale, and to non-discrimination for exercising these rights. The CPRA added a right to correct inaccurate personal information and created a new category of sensitive personal information with stricter handling requirements.

The California Privacy Protection Agency, created by the CPRA, began enforcement in 2023. Unlike GDPR enforcement which runs through national data protection authorities, this is a dedicated state agency. Fines are up to $2,500 per unintentional violation and $7,500 per intentional violation.

India's DPDP Act

India's Digital Personal Data Protection Act was signed into law in August 2023, making India the second most populous country in the world to enact a comprehensive privacy law. The rules and implementing regulations were still being finalized in early 2026, which has created uncertainty for businesses operating in the Indian market.

The DPDP Act applies to processing of digital personal data within India and to processing outside India if it involves personal data of Indian residents related to offering goods or services. It introduces the concept of a Data Fiduciary (roughly equivalent to GDPR's data controller) and a Data Principal (the individual whose data is processed).

Notable aspects include a consent-first approach, with limited grounds for processing without consent, and data localization requirements for certain categories of data that the government designates as significant. The Act also gives the government significant discretion to exempt certain data fiduciaries from specific provisions, which privacy advocates have criticized.

The rest of the global patchwork

Brazil's Lei Geral de Proteção de Dados (LGPD), effective 2020, closely follows GDPR structure and was enforced by the National Data Protection Authority starting in 2021. South Africa's POPIA (Protection of Personal Information Act) came into full force in 2021. Canada operates under PIPEDA for private sector data, with Quebec having passed Law 25 in 2022 as a substantially stricter provincial framework.

China enacted its Personal Information Protection Law (PIPL) in November 2021. It applies to processing of personal information of persons within China and has strict data localization requirements for critical information infrastructure operators. Cross-border transfers require a security assessment by the Cyberspace Administration of China for large data handlers.

The result is a world where a single global service may be simultaneously subject to GDPR, CCPA, LGPD, PIPL, and DPDP, each with different definitions, rights, and enforcement mechanisms.

What this means for websites and apps

For website operators, the practical implications start with IP address logging. Under GDPR, IP addresses are personal data. If your web server logs visitor IPs, you are processing personal data and need a lawful basis for it. Most sites rely on legitimate interests for security and analytics purposes, but this requires documentation.

Cookie banners exist because of the ePrivacy Directive, which predates GDPR but was interpreted more strictly after it. The requirement is real consent before setting non-essential cookies. The endless banners most sites implement are often poorly implemented and the subject of ongoing enforcement actions.

Data transfer restrictions under GDPR have made SaaS choices more complicated. Using a US-based analytics service, CRM, or CDN may constitute a transfer of EU personal data to a third country, requiring appropriate safeguards. The EU-US Data Privacy Framework agreed in 2022 restored some legal basis for these transfers, but its future depends on US law remaining stable.

Frequently asked questions

Does GDPR apply to my website if I'm based outside the EU?

If you are deliberately targeting EU residents or if EU residents can use your service, GDPR applies. Signs of deliberate targeting include offering prices in euros, mentioning EU shipping, or operating in EU languages. Merely being accessible from the EU does not automatically trigger it.

What counts as personal data under GDPR?

Any information that can be used to identify a living individual, directly or in combination with other data. This includes IP addresses, cookie IDs, device identifiers, and behavioral profiles tied to identifiers.

Do I need a cookie banner?

For cookies and tracking technologies that are not strictly necessary for the service to function, yes, under EU law. Strictly necessary cookies (session management, security) do not require consent. Analytics, advertising, and behavioral tracking cookies do.

What happens if I ignore GDPR?

Enforcement has been uneven but is increasing. DPAs can investigate complaints, conduct audits, and impose fines. The largest fines have been against major platforms, but SMEs have also been fined. The reputational damage of a publicized enforcement action often exceeds the financial penalty.

Check your domain's technical compliance: Site Check shows headers and security configuration.

Share Article:

Share Tool:

Tell your friends about our free IP analysis tool