The Role of GDPR and CCPA: Compliance Trends and Legal Loopholes
Keywords:
GDPR, CCPA, Data Protection, Privacy Law, Compliance, Legal Loopholes, Consent Mechanisms, Cross-border Data, Regulatory Enforcement, Digital RightsAbstract
This paper investigates the evolution of data privacy regulations, focusing on the General Data Protection Regulation (GDPR) of the European Union and the California Consumer Privacy Act (CCPA) in the United States. Through a comparative analysis, it explores compliance trends observed up to 2021, identifies prevalent legal loopholes, and examines the challenges organizations face in aligning with both frameworks. The study utilizes literature review, architecture models, sequence diagrams, and real-world case analytics to uncover the inefficiencies and interpret how the legal environment is shifting in response. Insights into regulatory architecture, corporate behavioral patterns, and enforcement gaps are presented to guide future policy development.
References
De Hert, P., & Papakonstantinou, V. (2018). The new General Data Protection Regulation: Still a sound system for the protection of individuals? Computer Law & Security Review, 34(2), 179–194. https://doi.org/10.1016/j.clsr.2017.01.001
Binns, R. (2020). Data protection impact assessments under the GDPR: A legal and empirical analysis. Computer Law & Security Review, 36, 105366. https://doi.org/10.1016/j.clsr.2019.105366
Swire, P., & Kennedy-Mayo, D. (2019). How CCPA Differs from GDPR. IAPP Whitepaper. https://iapp.org/resources/article/how-ccpa-differs-from-gdpr/
Tikkinen-Piri, C., Rohunen, A., & Markkula, J. (2018). EU General Data Protection Regulation: Changes and implications for personal data collecting companies. Computer Law & Security Review, 34(1), 134–153.
Koops, B.-J. (2014). The trouble with European data protection law. International Data Privacy Law, 4(4), 250–261. https://doi.org/10.1093/idpl/ipu023
Gellman, R. (2020). Fair Information Practices: A Basic History. https://bobgellman.com/rg-docs/rg-FIPshistory.pdf
Gurses, S., & van Hoboken, J. (2018). Privacy after the Agile Turn. IEEE Security & Privacy, 16(6), 13–21.
Zarsky, T. Z. (2016). Incompatible: The GDPR in the Age of Big Data. Seton Hall Law Review, 47, 995–1020.
Solove, D. J., & Hartzog, W. (2020). The FTC and the New Common Law of Privacy. Columbia Law Review, 114(3), 583–676.
Greenleaf, G. (2018). Global Data Privacy Laws 2017: 120 National Data Privacy Laws, Including Indonesia and Turkey. Privacy Laws & Business International Report, 145, 10–13.
Kuner, C. (2020). Reality and Illusion in EU Data Transfer Regulation Post-Schrems II. German Law Journal, 21(3), 881–894.
Cohen, J. E. (2019). Between Truth and Power: The Legal Constructions of Informational Capitalism. Oxford University Press.
Hoofnagle, C. J., Van der Sloot, B., & Zuiderveen Borgesius, F. J. (2019). The European Union general data protection regulation: What it is and what it means. Information & Communications Technology Law, 28(1), 65–98.
Chander, A., Kaminski, M. E., & McGeveran, W. (2020). Catalyzing Privacy Law. Georgetown Law Journal, 108(3), 597–654.
Gilliom, J., & Monahan, T. (2013). SuperVision: An Introduction to the Surveillance Society. University of Chicago Press.
Downloads
Published
Issue
Section
License
Copyright (c) 2023 International Journal of Computer Science and Engineering Research and Development (IJCSERD)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.




