The Role of GDPR and CCPA: Compliance Trends and Legal Loopholes

Authors

  • Arfi Siddik Mollashaik Solution Architect, Securiti.ai, USA Author

Keywords:

GDPR, CCPA, Data Protection, Privacy Law, Compliance, Legal Loopholes, Consent Mechanisms, Cross-border Data, Regulatory Enforcement, Digital Rights

Abstract

This paper investigates the evolution of data privacy regulations, focusing on the General Data Protection Regulation (GDPR) of the European Union and the California Consumer Privacy Act (CCPA) in the United States. Through a comparative analysis, it explores compliance trends observed up to 2021, identifies prevalent legal loopholes, and examines the challenges organizations face in aligning with both frameworks. The study utilizes literature review, architecture models, sequence diagrams, and real-world case analytics to uncover the inefficiencies and interpret how the legal environment is shifting in response. Insights into regulatory architecture, corporate behavioral patterns, and enforcement gaps are presented to guide future policy development.

References

De Hert, P., & Papakonstantinou, V. (2018). The new General Data Protection Regulation: Still a sound system for the protection of individuals? Computer Law & Security Review, 34(2), 179–194. https://doi.org/10.1016/j.clsr.2017.01.001

Binns, R. (2020). Data protection impact assessments under the GDPR: A legal and empirical analysis. Computer Law & Security Review, 36, 105366. https://doi.org/10.1016/j.clsr.2019.105366

Swire, P., & Kennedy-Mayo, D. (2019). How CCPA Differs from GDPR. IAPP Whitepaper. https://iapp.org/resources/article/how-ccpa-differs-from-gdpr/

Tikkinen-Piri, C., Rohunen, A., & Markkula, J. (2018). EU General Data Protection Regulation: Changes and implications for personal data collecting companies. Computer Law & Security Review, 34(1), 134–153.

Koops, B.-J. (2014). The trouble with European data protection law. International Data Privacy Law, 4(4), 250–261. https://doi.org/10.1093/idpl/ipu023

Gellman, R. (2020). Fair Information Practices: A Basic History. https://bobgellman.com/rg-docs/rg-FIPshistory.pdf

Gurses, S., & van Hoboken, J. (2018). Privacy after the Agile Turn. IEEE Security & Privacy, 16(6), 13–21.

Zarsky, T. Z. (2016). Incompatible: The GDPR in the Age of Big Data. Seton Hall Law Review, 47, 995–1020.

Solove, D. J., & Hartzog, W. (2020). The FTC and the New Common Law of Privacy. Columbia Law Review, 114(3), 583–676.

Greenleaf, G. (2018). Global Data Privacy Laws 2017: 120 National Data Privacy Laws, Including Indonesia and Turkey. Privacy Laws & Business International Report, 145, 10–13.

Kuner, C. (2020). Reality and Illusion in EU Data Transfer Regulation Post-Schrems II. German Law Journal, 21(3), 881–894.

Cohen, J. E. (2019). Between Truth and Power: The Legal Constructions of Informational Capitalism. Oxford University Press.

Hoofnagle, C. J., Van der Sloot, B., & Zuiderveen Borgesius, F. J. (2019). The European Union general data protection regulation: What it is and what it means. Information & Communications Technology Law, 28(1), 65–98.

Chander, A., Kaminski, M. E., & McGeveran, W. (2020). Catalyzing Privacy Law. Georgetown Law Journal, 108(3), 597–654.

Gilliom, J., & Monahan, T. (2013). SuperVision: An Introduction to the Surveillance Society. University of Chicago Press.

Downloads

Published

2023-04-16

How to Cite

Arfi Siddik Mollashaik. (2023). The Role of GDPR and CCPA: Compliance Trends and Legal Loopholes. International Journal of Computer Science and Engineering Research and Development (IJCSERD), 13(1), 44-57. https://ijcserd.in/index.php/home/article/view/IJCSERD_13_01_003