Data Privacy & User Rights

CCPA vs GDPR vs DPDP: User Rights for Global Websites

Map CCPA, GDPR, and DPDP Act user rights for global websites: access, delete, correct, opt-out versus consent withdrawal, clocks, and one intake stack.

Working summary: Global websites often face CCPA/CPRA, GDPR, and India’s DPDP Act at once. Labels differ (consumer, data subject, Data Principal), and so do clocks, opt-outs, and lawful bases. Build one intake hub with region-aware request types rather than one button for every law.

  • Access: CCPA know, GDPR Article 15, DPDP Section 11 summary and sharing list each need different response packs.
  • Delete: CCPA 1798.105, GDPR Article 17, and DPDP Section 12(3) share the idea but not the exceptions or fan-out duties.
  • Opt-out vs withdraw: CCPA sale/share opt-out is not EU consent withdrawal or DPDP Section 6 cessation.
  • Clocks: CCPA often 45 days; GDPR generally one month; DPDP grievance publish period at most 90 days.
  • Route by residency: Geo-detect, verify proportionately, and fan out to processors under each statute.

Global websites often face three user-rights regimes at once: California’s CCPA (as amended by the CPRA), the EU GDPR, and India’s DPDP Act. The labels differ (consumer, data subject, Data Principal), and so do clocks, opt-outs, and lawful bases. This guide maps the rights that matter for product and privacy teams running one intake stack across regions.

For deeper India and EU consent detail, see GDPR vs DPDP: User Rights and Consent Compared and DPDP Act User Rights: A Practical Guide for Indian Websites. Notice drafting is covered in How to Write a Privacy Policy That Covers User Rights. Tooling walkthroughs live in How to Handle DSARs with OneTrust and OneTrust DSAR Automation: Setup and Best Practices.

GDPR has been in force since 25 May 2018; CCPA/CPRA consumer rights are in force under California Civil Code Title 1.81.5 (with statute text maintained by the California Privacy Protection Agency); DPDP Act Sections 11 to 17 are scheduled to become operative on once Rules and commencement are notified under forthcoming MeitY commencement notifications.

Who is covered (simplified)

Topic CCPA / CPRA (California) GDPR (EU/EEA) DPDP Act (India)
Protected person Consumer (California resident) Data subject Data Principal
Covered organisation “Business” meeting CCPA thresholds and doing business in California Controller / processor with Art 2 to 3 triggers Data Fiduciary / Data Processor under Section 3
Core statute Cal. Civ. Code sections 1798.100 et seq. Regulation (EU) 2016/679 Act No. 22 of 2023

Geo-route request forms by residency and service location. Do not assume a California opt-out button satisfies DPDP consent withdrawal or GDPR erasure.

Rights side by side

Know / access

  • CCPA section 1798.110: right to know what personal information is collected, including categories, sources, purposes, categories of third parties, and specific pieces upon a verifiable consumer request (with related disclosure duties in section 1798.130).
  • GDPR Article 15: confirmation of processing, access to the personal data, and the listed information set (purposes, recipients, retention, rights, and more).
  • DPDP Act Section 11: for consent-backed processing (including Section 7(a)), a summary of personal data and processing activities; identities of other fiduciaries and processors with whom data was shared, plus a description of what was shared; and other prescribed information.

Delete / erasure

  • CCPA section 1798.105: right to request deletion of personal information the business collected from the consumer, with duties to delete and to notify service providers, contractors, and (unless impossible or disproportionate) third parties to whom the business sold or shared the information; statutory exceptions apply.
  • GDPR Article 17: erasure without undue delay where listed grounds apply, subject to Article 17(3) exceptions.
  • DPDP Act Section 12(3): erase on request unless retention is necessary for the specified purpose or for compliance with law; Section 8(7) also drives erasure on consent withdrawal or when purpose is no longer served.

Correct

  • CCPA section 1798.106: right to correct inaccurate personal information the business maintains about the consumer.
  • GDPR Article 16: rectification without undue delay; complete incomplete data.
  • DPDP Act Section 12(2): correct inaccurate or misleading data; complete incomplete data; update personal data.
  • CCPA section 1798.120: right to opt out of sale or sharing of personal information. Section 1798.121 adds the right to limit use and disclosure of sensitive personal information in defined cases. These are not the same as EU consent withdrawal.
  • GDPR: withdraw consent (Article 7(3)); object to certain processing (Article 21); separate ePrivacy rules often govern cookies.
  • DPDP Act Section 6(4) to (6): withdraw consent with comparable ease; fiduciary must cease and cause processors to cease within a reasonable time unless other law authorises processing.

For website withdrawal UX under DPDP and GDPR, see Consent Withdrawal Under DPDP and GDPR.

Other rights global teams trip over

Right CCPA / CPRA GDPR DPDP Act
Portability Deliver information in a readily useable format that allows transmission without hindrance (see section 1798.130 response rules) Article 20 No direct Chapter III twin
Restriction of processing Not framed like GDPR Art 18 Article 18 No direct Chapter III twin
Nomination Not a CCPA twin of DPDP Section 14 Not a GDPR Chapter III twin Section 14; Rules 2025 Rule 14(4)
Non-retaliation / non-discrimination Right not to be retaliated against for exercising CCPA rights (see statute and CPPA materials) Processing must still meet Art 5 principles; consent must be free Section 15 duties on principals; fiduciary obligations remain
Grievance before regulator CPPA enforcement; consumer requests first to the business Complaint to supervisory authority (Art 77) Section 13 grievance with fiduciary first; exhaust before Board

Response clocks

  • CCPA: businesses generally must respond to verifiable know, delete, and correct requests within 45 days of receipt, with one additional 45-day extension when reasonably necessary and with notice to the consumer (see section 1798.130).
  • GDPR Article 12(3): generally within one month; extend by up to two further months for complex or numerous requests, with notice.
  • DPDP Act: Section 13(2) points to a prescribed grievance period; Rules 2025 Rule 14(3) requires publishing a grievance response period not exceeding ninety days.

Set internal SLAs to the strictest clock that applies to that requester.

Lawful processing contrast (why forms differ)

  • GDPR: six Article 6 bases; consent is only one. Special category data needs Article 9.
  • DPDP Act: consent (Section 6) or certain legitimate uses (Section 7). No GDPR-style open legitimate-interests balancing test.
  • CCPA: not built as an EU-style lawful-basis regime. It centres notice, consumer rights, sale/share opt-out, sensitive PI limits, and contracts with service providers. Do not paste “legitimate interests” into a California notice without counsel.

Global website build pattern

  1. Detect region (account country, shipping address, or declared residency) and show the matching rights set.
  2. One hub, many request types: access/know, delete, correct, CCPA sale/share opt-out, limit sensitive PI, GDPR withdraw consent / object, DPDP grievance and nomination.
  3. Verification intensity: CCPA speaks in “verifiable consumer request” terms; GDPR and DPDP expect proportionate identity checks. Avoid over-collecting ID for simple opt-outs.
  4. Downstream fan-out: CCPA deletion expects service provider and, where required, third-party notices; DPDP Section 6(6) and 8(7) require processor cessation and erasure; GDPR needs recipients informed under Articles 17 and 19 where applicable.
  5. Privacy policy: layer California “Notice at Collection”, GDPR Articles 13/14, and DPDP Section 5 / Rule 3 content rather than one US-only template.

Quick routing matrix for support

User signal Primary playbook
California resident; “Do Not Sell or Share” CCPA section 1798.120 opt-out; update GPC/signal handling if you honour it
EU resident; “delete my data” GDPR Article 17 assessment; check other Art 6 bases and Art 17(3)
India resident; “summary of my data” DPDP Section 11 pack (from Rules commencement); not only a raw file dump
India resident; “stop using my data for marketing” Section 6 withdrawal; cease processors; optional separate erasure ticket

Sources

  • California Civil Code sections 1798.105, 1798.106, 1798.110, 1798.120, 1798.121, 1798.130: California Legislative Information; CPPA statute PDF: CCPA statute (CPPA).
  • Regulation (EU) 2016/679, Articles 6, 7, 12, 15 to 21, 77: EUR-Lex.
  • Digital Personal Data Protection Act, 2023, Sections 3, 6, 7, 8, 11 to 14; MeitY forthcoming MeitY commencement notifications; forthcoming DPDP Rules, Rule 14: MeitY PDF.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 19 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *