Opening Scene
A traveler who has just mastered the EU’s entry requirements might reasonably assume every other border works the same way, only to discover that California’s checkpoint asks different questions, Brazil’s wants different paperwork, and a dozen other countries are busy writing their own rulebooks entirely. None of these borders coordinate with each other. Each one simply decided, on its own timeline and for its own reasons, that personal data deserved a checkpoint.
In Plain English
The California Consumer Privacy Act (CCPA), later strengthened by the California Privacy Rights Act (CPRA), and Brazil’s Lei Geral de Proteção de Dados (LGPD) are two of the most significant privacy laws written after GDPR, and both borrow heavily from its structure while diverging in meaningful ways. CCPA frames privacy primarily around consumer rights — the right to know what data is collected, to opt out of its sale, and to request deletion — while LGPD, much like GDPR, is built around lawful bases for processing. The practical result for any organization operating across borders is a genuine patchwork: broadly similar goals, but different specific obligations depending on whose data you’re handling and from where.
The Old Way
Before CCPA and LGPD existed as functioning, enforced laws:
- The United States had no comprehensive federal privacy law and still doesn’t, leaving American consumers with meaningfully less formal protection than their European counterparts.
- Brazil, like most of Latin America, handled data protection through a scattering of sector-specific rules rather than one unified framework, making enforcement inconsistent and coverage full of gaps.
- Companies operating in both regions often applied a single, GDPR-only compliance approach and simply hoped it would be close enough to satisfy whatever else might apply, which was never a safe bet.
CCPA and LGPD each closed that gap for their own jurisdiction, giving California and Brazil their own genuine, enforceable checkpoint rather than relying on borrowed European rules to cover the distance.
What’s Changing (and Why AI Is the Reason)
- The number of jurisdictions writing comprehensive privacy laws keeps expanding — most U.S. states now have their own statute, and dozens of countries beyond Brazil have followed a broadly similar path since GDPR set the template.
- This expanding patchwork is exactly the kind of multi-jurisdiction complexity covered from the security angle in this content library’s dedicated access control and data security series, where the same personal data often has to satisfy different regional rules simultaneously depending on where it’s stored and accessed.
- AI companies training models on data scraped or licensed from multiple regions now have to reconcile CCPA’s opt-out model with LGPD’s and GDPR’s consent-based models within a single training pipeline, which is a genuinely harder engineering problem than complying with any one law in isolation.
The Metaphor, Fully Extended
| Multiple National Borders | The Privacy Law Patchwork |
|---|---|
| Each country writing its own entry requirements independently | Each jurisdiction writing its own privacy statute independently |
| A traveler needing different paperwork depending on destination | An organization needing different compliance measures depending on whose data it holds |
| Some borders emphasizing visas, others emphasizing traveler rights on entry | CCPA’s consumer-rights framing versus LGPD’s and GDPR’s lawful-basis framing |
| A travel agency mapping which documents are needed for which trip | A compliance program mapping which law applies to which category of personal data |
For Beginners: What to Actually Do
- Learn the core difference in approach: CCPA centers on consumer rights like opting out of data sales, while LGPD centers on lawful bases similar to GDPR.
- Recognize that “complying with GDPR” does not automatically mean complying with CCPA, LGPD, or any other jurisdiction’s law.
- Start tracking, informally, which U.S. states beyond California have passed their own comprehensive privacy laws, since that list keeps growing.
For Practitioners and Leaders: The Deeper Layer
- Build a jurisdiction map that identifies exactly which privacy laws apply to which categories of data your organization holds, rather than defaulting to a single global standard.
- Coordinate this mapping work with the regional data-residency and access considerations covered in this content library’s dedicated access control and data security series, since legal applicability and technical storage location are closely linked.
- For any AI training pipeline touching data from multiple regions, design the consent and opt-out handling to satisfy the strictest applicable regime rather than patching in exceptions after the fact.
Quick Recap
- CCPA and LGPD are two of the most significant privacy laws to follow GDPR, each with a genuinely different structural approach.
- CCPA emphasizes consumer rights like the right to opt out of data sales; LGPD, like GDPR, is built around lawful bases for processing.
- The number of jurisdictions with comprehensive privacy laws keeps growing, creating a genuine patchwork rather than one global standard.
- Reconciling multiple regimes within a single AI training pipeline is a harder problem than complying with any one law alone.
Where This Fits in the Series
Article 2 covered GDPR as the template most later privacy laws borrowed from. Article 4 steps back from any single jurisdiction’s rules to ask a more foundational question that every one of these laws depends on: what actually counts as personal data in the first place, and what doesn’t.
Subscribe to the Newsletter
Get the latest DataParables articles delivered straight to your inbox.