Skip to main content
Smartbox.ai

Guides3 min read

Data Subject Access Requests Under GDPR and CCPA

But with the sheer amount of data being created in the world today, it is a constant challenge to keep it protected

Data Subject Access Requests Under GDPR and CCPA

Keeping data safe is absolutely imperative for every business, regardless of size, sector, vertical or specialisation.

But with the sheer amount of data being created in the world today, it is a constant challenge to keep it protected. Nobody wants their sensitive information and personal data falling into the wrong hands.

This is why legislation such as the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) has been put in place to provide rules and guidelines for businesses that handle data. There is other legislation, but these two are the focus of this blog and how they differ, yet often work together.

Privacy and data protection is big business for fraudsters, who extort billions every year from data breaches and holding companies to ransom. According to market research company Cybersecurity Ventures the global annual cost of cybercrime is set to reach $9.5 trillion in 2024, rising to $10.5 trillion by 2025.

Being the victim of a breach is a costly exercise both financially and emotionally. It can even cause a company to go out of business, resulting in job losses and leaving both customers and creditors out of pocket.

A Costly Business

According to a report by the Ponémon institute – the average cost of a data breach in 2023 was $4.45 million – up 2.25% from 2022. The top three hardest hit industries were healthcare, followed by the financial industry and the public sector in third place. Phishing and compromised credentials were the most common initial attacks – responsible for 16% and 15% of breaches respectively.

Few companies in operation today can avoid the shadow of GDPR – a legislative framework designed by the European Union to safeguard the privacy and data protection rights of its EU citizens. This has been in force since May 2018.

GDPR governs how businesses – through their website and apps – should handle personal customer data such as names, email addresses, location and IP addresses, plus more. The user is given the deciding power to choose how businesses use their personal information, usually by filling out an online consent form.

However, the lesser-known/cited California Consumer Privacy Act (CCPA) is also legislation that could affect many firms globally and has been in force since July 2020. Any business, regardless of where they are based, would need to be CCPA compliant if they are processing the data of more than 50,000 Californians annually. Under CCPA rules, users have the right to request businesses delete their personal information and opt out of selling their personal information to third parties.

The penalties for data breaches can be huge. Under GDPR rules, companies will not only have to cover the costs of the breach, but could face huge fines as well – $20 million, or four per cent of its annual turnover, whichever is higher. Under CCPA rules, penalties are lighter – $2500 for unintentional violations, $7500 for intentional violations and up to $750 damages in civil court.

But in reality, nobody wants to be paying a fine for compromising their customers’ data. Reputations can be damaged and trust lost.

In the box below, the similarities and differences between GDPR and CCPA when it comes to user rights can be clearly seen.

**The different user rights under GDPR and CCPA: **

**User rights under GDPR **

User rights under CCPA

The Right to Information

The Right to Opt Out

The Right of Access

The Right to be Informed

The Right to Rectification

The Right to Disclosure

The Right to Erasure

The Right to Deletion

The Right to Restriction of Processing

The Right to Equal Services and Prices

The Right to Data Portability

The Right to Object

Of course, businesses have to collect data on their customers. Without it, there is no way of improving services and products, providing a personal touch to marketing or sales collateral, and measuring growth and success in different regions.

Being aware of the different compliance laws and the impact they could have on your business if a breach should occur is something every management team in every company today should be aware of. Compliance with these laws can also be used as a tool to reassure customers that data protection is taken very seriously indeed.

Request your Demo with one of our experts: https://smartbox.ai/book-a-demo

Topics

  • DSAR
  • GDPR
  • CCPA

← Back to all articles

See Smartbox on data like yours.

A 30-minute demo with a product expert — your files or ours.

Book a demo

We use cookies to measure how the site is used, and — if you agree — to measure our advertising. You can accept one without the other, and declining is one click. See our cookie policy.