Privacy regulations
Respecting a user's privacy is not just a good practice and a way to build trust: it's legally required in various jurisdictions. This section describes the most important regulations, the conditions in which a website is required to comply, and what compliance looks like.
GDPR: Europe's privacy law
The GDPR, is the European Union's data protection law. The GDPR governs how organizations handle the personal data of EU residents. It gives individuals control over their own data and unifies data protection regulations across EU member states.
The GDPR applies to anyone collecting and processing personal data belonging to any EU resident. Users must explicitly agree to providing their data, unless another lawful basis applies such as a contract or legal obligation.
CCPA: California's privacy law
The CCPA is a California privacy law giving California residents rights over their personal information. The CCPA creates requirements on businesses that collect, use, or share that data, including rights to know, delete, opt out, correct, and limit the use of sensitive data.
The CCPA only applies to for-profit businesses that are over a certain size or that engage to a specific degree in buying, selling, or sharing the personal information of California residents.
It allows businesses to collect and use personal information by default but give data subjects the right to opt out of the sale or sharing of personal information and the right to limit the use of their sensitive personal information. One mechanism for opting out is the Global Privacy Control (GPC) signal.