> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# GDPR and the CCPA: Testimony Before the California Senate Judiciary Committee
- URL: https://www.thedelatorrereview.com/gdpr-and-the-ccpa-testimony-before-the-california-senate-judiciary-committee/
- Published: 2019-03-05T13:57:00.000Z
- Updated: 2026-08-22T14:14:36.000Z
- Description: A look back at my 2019 testimony before the California Senate Judiciary Committee, explaining the GDPR, its historical foundations and core principles, and how Europe’s approach to data protection compared with California’s newly enacted CCPA.
- Author: Lydia
- Tags: Legal History, California Consumer Privacy Act (CCPA), GDPR

---

### Historical Context

I was invited by Senator Hannah-Beth Jackson, then Chair of the **California Senate Judiciary Committee,** to testify at the **Committee’s March 5, 2019 informational hearing, *The State of Data Privacy Protection: Exploring the California Consumer Privacy Act and its European Counterpart*.** The hearing took place shortly after enactment of the **California Consumer Privacy Act (CCPA)** and before it became operative. The Legislature was considering additional amendments to the new law and sought to examine the CCPA alongside other regulatory models—particularly the **EU General Data Protection Regulation (GDPR)**—as it considered how California’s new privacy framework should develop. 

I participated in the panel devoted to comparing the CCPA with its counterparts and examining compliance, where my role was to provide the Committee with an overview of the GDPR and the European approach to data protection. **I am sharing my testimony here because it provides both a snapshot of an important moment in the development of California privacy law and an accessible introduction to the historical foundations and core principles of European data protection law.** Much has changed in California privacy law since 2019, but the fundamental GDPR concepts discussed in the testimony remain relevant today.

---

## Testimony

Thank you, Senator Jackson and members of this committee, for giving me the opportunity to participate.

  
My name is **Lydia de la Torre**, and I am the Privacy Fellow at **Santa Clara School of Law**, where I co-direct the privacy program and teach comparative privacy law. I am licensed to practice law both in Spain and in California and, prior to joining Santa Clara, I worked in the private sector — both as outside counsel and as an in-house privacy attorney.

I have been asked to use my time to provide a general overview of what the GDPR is.

### **What is the GDPR?**

**GDPR** stands for [**General Data Protection Regulation**](https://www.thedelatorrereview.com/gpdr/), and it is one of three laws that implement the right to data protection in the European Union (EU). The other two (1) are rarely discussed in the United States because they apply to the public sector and, therefore, do not affect U.S. organizations.

In the EU, the **right to data protection** is a fundamental right enshrined in **Article 8 of the Charter of Fundamental Rights**, which is the EU’s functional equivalent to the U.S. Bill of Rights. In addition, the constitutions of some EU countries provide for a right to data protection. For example, **Article 18.4 of the Spanish Constitution** grants Spaniards a right to data protection (2).

In addition to having a right to data protection, Europeans also have a right to privacy. The right to privacy is protected under Article 7 of the Charter and is recognized by most, if not all, Member State constitutions. The only area of privacy regulated at the EU level is communications privacy. In 2002, the e-Privacy Directive (3) imposed restrictions on the collection, access, and use of communications data, and mandated certain security measures. It also established consent rules for direct marketing and is, in that sense, the EU counterpart to the U.S. [**CAN-SPAM Act**](https://www.thedelatorrereview.com/the-can-spam-act-explained-a-practical-guide-to-u-s-email-marketing-compliance/). The e-Privacy Directive was nicknamed the *“Cookie Directive”* because it led to the implementation of so-called “cookie walls” on EU websites (4).

A helpful analogy to understand the right to data protection in Europe is this: in the same way that U.S. citizens have a constitutional right to bear arms — distinct from but connected to their right to self-defense — Europeans have a right to data protection, which is distinct from yet connected to their right to privacy.

### **Historical context**

The origin of the right to data protection can be traced back to the rise of automated data processing in the 1960s and 1970s. At the time, the virtues and risks of what we now call computers were debated on both sides of the Atlantic. In the United States, the consensus was that no overarching new regulation was needed. Europeans came to the opposite conclusion and decided to enact a new type of law regulating how computers are allowed to “think” about humans. The original name given to this new legal field was *“protection of individuals with regard to automated processing of personal data.”* This name was clearly too long and was eventually shortened to *Data Protection Law*.

The **Council of Europe** (an international organization to which all EU countries belong) played a key role in developing data protection law. In 1973 and 1974, it issued two influential resolutions that laid down the data-processing principles embedded today in the GDPR. Most importantly, on **January 28, 1981**, the Council opened for signature the [***Convention for the Protection of Individuals with Regard to Automated Processing of Personal Data***](https://www.thedelatorrereview.com/convention-108-explained-the-international-treaty-that-shaped-modern-data-protection/) (known as *Convention 108*). This convention is the seed from which the right to data protection sprouted, and it remains to this day the only binding international agreement in the field of data protection law. Incidentally, it is the reason why Europeans celebrate **Data Protection Day** annually on January 28.

### Tenets of EU data protection law

The first pan-European data protection law was enacted in 1995 (5) and remained in effect until it was repealed by the GDPR in 2016\. Its framework was built on four core tenets that have proven strong enough to drive effective compliance yet flexible enough to adapt to the ever-changing nature of technology. These tenets were not changed by the GDPR.

I will briefly discuss them and offer correlations to the CCPA.

#### **FIRST TENET: Technology must be built to serve humankind**

In the words of Apple’s CEO: *“Technology is capable of doing great things. But it doesn’t want to do great things. It doesn’t want anything. That part takes all of us.”* (6)

The overarching goal of data protection law, as described in [Recital 4 of the GDPR,](https://gdpr-info.eu/recitals/no-4/?ref=thedelatorrereview.com) is to ensure that technology is designed *“to serve mankind.”*

To prevent unethical uses of technology, data protection law distinguishes between permissible and non-permissible purposes. EU law identifies six lawful bases that constitute the universe of what is permissible and outlaws the use of personal data for any purpose falling outside those bases. It could be said that, under the GDPR, one is ‘guilty’ of unlawful processing until a lawful basis is identified.

Europe’s history likely explains this restrictive approach. Although lawmakers saw technology’s potential for good, the question of how the Holocaust might have looked if a database tracking citizens’ whereabouts and religion had existed was probably not far from their minds.

The CCPA does not adopt the GDPR’s restrictive general rule but does incorporate the idea of **purpose limitation**. Specifically, the CCPA subjects the sharing of personal information for certain “commercial purposes” to a right to opt out for adults and a right to opt in for minors. In contrast to the GDPR (which does not define the conduct it restricts), the CCPA explicitly defines the conduct (“data sale”) it restricts.

#### **SECOND TENET: Factual control = accountability**

Under EU data protection law, accountability for data handling is directly proportional to factual control. Any entity that “alone or jointly with others determines the purposes and means of processing personal data” is a **controller**. Entities that act “on behalf of” controllers are **processors**. Because Europeans see data protection as a **fundamental right**, very few organizations are exempt from the GDPR. By limiting exemptions and equating control with accountability, the GDPR effectively creates an unbreakable **chain of custody** over personal data.

The **CCPA** ties control to accountability by incorporating the concept of “controller” into its definition of “business,” and the concept of “processor” into its definition of “service provider.” However, the CCPA applies only to entities meeting certain thresholds, meaning significant amounts of personal information fall outside its scope. Thus, the chain of custody can be interrupted — but, since the CCPA equates control with accountability, the chain will not break entirely. As data changes hands, whenever an entity that meets the CCPA thresholds gains effective control, its data practices and those of its service providers must comply with the law. For example, a data broker meeting those thresholds is subject to the CCPA, even if it collects data exclusively from sources not covered by the Act and has no direct relationship with the individuals concerned.

#### **THIRD TENET: If you can connect it, we will regulate it**

The line between “private and sensitive” and “public and harmless” is blurry today. Advances in technology enable identification of individuals based on data that seems random, and make it possible to derive sensitive information from mundane data sets. For example, researchers have found that 95% of cellphone users can be uniquely identified using only four spatio-temporal points (7). This fluidity has hamstrung legal frameworks that limit their scope to inherently “private” or “sensitive” data.

European data protection law restricts the processing of personal data, defined as “information relating to an identified or identifiable natural person.” Though short, this definition is interpreted broadly by courts and data protection authorities.

Information need not be private or confidential to be subject to the GDPR. Some of the most public facts about us — including our names — are unquestionably personal. Proof of a special interest to prevent dissemination or misuse is unnecessary, and establishing a “reasonable expectation of privacy” is not required. Therefore, publicly available data is subject to the GDPR so long as it is personal in nature.

Similarly, data need not be sensitive. [**Article 9 of the GDPR**](https://gdpr-info.eu/art-9-gdpr/?ref=thedelatorrereview.com) places additional restrictions on processing information that has historically been a vector for discrimination, such as race, religion, political affiliation, or sexual orientation (so-called “special categories”). However, there is no minimum threshold of sensitivity below which the GDPR does not apply.

The definition of personal information under the CCPA is more comprehensive than any existing definition under California law. It includes data elements that, in and of themselves, are neither private nor sensitive. Some argue that the CCPA regulates data not covered under the GDPR. I personally cannot imagine how any interpretation of the CCPA could yield that outcome, especially when it excludes data types (such as anonymized and aggregated data) that are also excluded from the GDPR.

#### **FOURTH TENET: Transparency is the path to fairness**

A key goal of data protection law has always been to enhance the transparency of data processing. Transparency is viewed as a prerequisite for fairness because, in many ways, compliance with data protection law is a “black box.”  
From granting individuals the [right to be informed](https://www.thedelatorrereview.com/what-is-the-right-to-be-informed-under-the-gdpr/) and the [right of access](https://www.thedelatorrereview.com/what-is-the-right-of-access-under-the-gdpr/), to requiring the creation of data management policies, imposing r[ecord-keeping obligations](https://www.thedelatorrereview.com/gdpr-records-of-processing-activities-ropas-explained-a-practical-guide-to-article-30/), mandating [Data Protection Officers](https://www.thedelatorrereview.com/the-gdpr-data-protection-officer-dpo-explained-when-you-need-one-and-what-they-do/), and enabling a private right of action, many GDPR provisions exist to ensure transparency.

The CCPA goes further than any existing U.S. federal or state law in including transparency-enhancing provisions and, most notably, gives Californians a right to access their personal information. However, it does not go as far as the GDPR.

As a final point, in my experience, protecting personal data requires (1) appointing independent, well-trained professionals to managerial positions, and (2) establishing mechanisms that effectively protect them when they raise issues internally. The CCPA does not specifically require appointing compliance officers, and California law offers no meaningful protections to privacy professionals — despite their function as embedded regulatory enforcers, sometimes in unfriendly environments. Empowering and protecting these professionals would, in my view, go a long way toward ensuring effective privacy protection for California residents.

### Conclusion

In conclusion, in addition to having a right to privacy, Europeans also have a right to data protection. The GDPR is one of the EU’s three data protection laws. Its stated goal is to ensure that technology is built to *serve mankind* and, to this end, it allows the use of personal data only for ethical purposes, creates an unbreakable chain of custody by equating accountability with factual control, and includes many transparency-enhancing provisions.

The **CCPA** represents an innovative approach to privacy enforcement in California and, although not modeled after the GDPR, it incorporates several elements that have formed the core compliance structure of European data protection law since 1995.

I again thank the Chair and members of the committee for the opportunity to participate in this hearing, and I look forward to your questions.

**Endnotes:**

1. Regulation (EU) 2018/1725, governing the processing of personal data by EU institutions, bodies, offices and agencies, and Directive (EU) 2016/680 (the Law Enforcement Directive), governing the processing of personal data by competent authorities for law-enforcement purposes.
2. Article 18.4 of the Constitution of Spain states:

> “The law shall restrict the use of data processing in order to guarantee the honour and personal and family privacy of citizens and the full exercise of their rights.”

> NOTE: In 1992 (that is to say, three years before the EU 1995 data protection directive was enacted) Spain enacted its first data protection law: The organic law 5/1992, of October 29, regulating the processing of personal data through automated means (LORTAD).

1. Directive 2002/58/EC (ePrivacy Directive), as amended by Directive 2009/136/EC
2. Cookiewalls are ‘pop-ups’ placed on a website to inform users about the website’s online tracking policies.
3. Directive 95/46/EC
4. This remarks were provided October 24th of last year at the International Conference of Data Protection & Privacy Commissioners in Brussels, the CEO of Apple was a keynote speaker
5. “[Unique in the Crowd: The privacy bounds of human mobility](https://www.nature.com/articles/srep01376?ref=thedelatorrereview.com)” 2013 Scientific Reports article by [Yves-Alexandre de Montjoye](https://www.nature.com/articles/srep01376?ref=thedelatorrereview.com#auth-1), [César A. Hidalgo](https://www.nature.com/articles/srep01376?ref=thedelatorrereview.com#auth-2), [Michel Verleysen](https://www.nature.com/articles/srep01376?ref=thedelatorrereview.com#auth-3) & [Vincent D. Blondel](https://www.nature.com/articles/srep01376?ref=thedelatorrereview.com#auth-4)

---

### Additional Resources: 

### **California Senate Judiciary Committee Hearing Materials**

- [**The State of Privacy Protection: Exploring the California Consumer’s Privacy Act and its European Counterpart**](https://sjud.senate.ca.gov/sites/sjud.senate.ca.gov/files/sjud%5Fprivacy%5Fhearing%5Fbackground%5Fcorrected.pdf?ref=thedelatorrereview.com) — Background paper prepared by Senate Judiciary Committee staff for the hearing.
- [**Hearing Agenda**](https://sjud.senate.ca.gov/sites/sjud.senate.ca.gov/files/sjud%5Fprivacy%5Fhearing%5Fagenda%5Fcorrected.pdf?ref=thedelatorrereview.com) — Agenda for the California Senate Judiciary Committee hearing.
- [**Video of the Hearing**](http://calchannel.granicus.com/MediaPlayer.php?view%5Fid=7&clip%5Fid=5957&ref=thedelatorrereview.com) — Video recording of the hearing.

### **Related Resources from The de la Torre Review**

For readers interested in exploring the concepts discussed in this testimony in greater depth:

- [**EU Data Protection Law and the General Data Protection Regulation (GDPR)**](https://www.thedelatorrereview.com/gpdr/) — A comprehensive guide to European data protection law and the GDPR, including its historical foundations, scope, core concepts, principles, lawful bases, individual rights, and principal compliance obligations.
- [**Convention 108 Explained: The International Treaty That Shaped Modern Data Protection**](https://www.thedelatorrereview.com/convention-108-explained-the-international-treaty-that-shaped-modern-data-protection/) — Explains the origins and development of Convention 108, the Council of Europe’s landmark data protection treaty, and its modernization through Convention 108+.
- [**When Everything Is “Personal”: GDPR vs. CCPA**](https://www.thedelatorrereview.com/when-everything-is-personal-gdpr-vs-ccpa/) — Compares the GDPR’s concept of “personal data” with the CCPA/CPRA’s definition of “personal information,” including the treatment of public, pseudonymous, hashed, deidentified, and household data.
- [**What Is Data Protection Law?**](https://www.thedelatorrereview.com/what-is-data-protection-law/) — Explains why European data protection law is distinct from traditional privacy law and how it developed as a legal framework governing the processing of personal data.
- [**What Is the Charter of Fundamental Rights?** ](https://www.thedelatorrereview.com/what-is-the-charter-of-fundamental-rights-of-the-european-union/)— Introduces the EU Charter of Fundamental Rights and explains the separate protections for privacy under Article 7 and the protection of personal data under Article 8.
- [**Constitutional Data Protection Law**](https://www.thedelatorrereview.com/constitutional-data-protection-law/) — Examines the development of data protection as a fundamental and constitutional right in Europe, including its relationship to the separate right to privacy.
- [**What Was the Article 29 Working Party?** ](https://www.thedelatorrereview.com/what-was-the-article-29-working-party/)— Explains the role of the Article 29 Working Party (WP29), which developed influential interpretations of European data protection law before being replaced by the European Data Protection Board under the GDPR.
- [**Territorial Scope of the GDPR** ](https://www.thedelatorrereview.com/territorial-scope-of-gdpr/)— Explains when the GDPR applies to organizations inside and outside the European Union, including its extraterritorial application to certain organizations offering goods or services to, or monitoring, individuals in the EU.
- [**Material Scope of the GDPR**](https://www.thedelatorrereview.com/material-scope-of-the-gdpr/) — Examines the types of personal-data processing governed by the GDPR and the activities that fall outside its material scope.
- [**What Is a Controller?** ](https://www.thedelatorrereview.com/what-is-a-controller/)— Explains the GDPR concept of a controller: the person or organization that determines the purposes and means of processing personal data.
- [**What Is a Processor?** ](https://www.thedelatorrereview.com/what-is-a-processor/)— Explains the role of processors that handle personal data on behalf of controllers and the GDPR obligations associated with that role.
- [**What Is “Personal Data” Under EU Data Protection Law?** ](https://www.thedelatorrereview.com/what-is-personal-data-under-eu-data-protection-law/)— Examines the GDPR’s deliberately broad definition of personal data and the concept of information “relating to” an identified or identifiable natural person.
- [**What Are “Special Categories of Data” Under the GDPR?**](https://www.thedelatorrereview.com/what-are-special-categories-of-data-under-the-gdpr/) — Explains the categories of personal data receiving enhanced protection under Article 9 and the additional conditions that must be satisfied before such data may be processed.
- [**What Does “Lawfulness, Fairness and Transparency” Mean Under the GDPR?**](https://www.thedelatorrereview.com/what-does-lawfulness-fairness-and-transparency-mean-under-the-gdpr/) — Examines the first Article 5 principle and the requirements that personal-data processing be lawful, fair, and transparent.
- [**What Does “Purpose Limitation” Mean Under the GDPR?**](https://www.thedelatorrereview.com/what-does-purpose-limitation-mean-under-the-gdpr/) — Explains the requirement to collect personal data for specified, explicit, and legitimate purposes and the restrictions on subsequent incompatible uses.
- [**What Is “Data Minimization” Under the GDPR?**](https://www.thedelatorrereview.com/what-is-data-minimization-under-the-gdpr/) — Explains why organizations should limit personal data to what is adequate, relevant, and necessary for the purposes for which it is processed.
- [**What Does “Accountability” Mean Under the GDPR?**](https://www.thedelatorrereview.com/what-does-accountability-mean-under-the-gdpr/) — Examines the GDPR principle requiring controllers not merely to comply with data protection requirements but also to be able to demonstrate that compliance. The GDPR overview identifies accountability as one of its seven core principles.
- [**What Is “Consent” Under the GDPR?**](https://www.thedelatorrereview.com/what-is-consent-under-the-gdpr/) — Explains consent as one of the GDPR’s six lawful bases for processing and the requirements that must be satisfied for consent to be valid.
- [**What Are “Legitimate Interests” Under the GDPR?**](https://www.thedelatorrereview.com/what-are-legitimate-interests-under-the-gdpr/) — Examines when controllers may rely on legitimate interests as a lawful basis and the balancing required between those interests and individuals’ rights and freedoms.
- [**What Is the “Right of Access” Under the GDPR?**](https://www.thedelatorrereview.com/what-is-the-right-of-access-under-the-gdpr/) — Explains the right of individuals to determine whether their personal data is being processed and to obtain a copy of their data and information about that processing, including applicable limitations and response requirements.
- [**What is the "Right to Erasure" (or "Right to be Forgotten") under the GDPR?**](https://www.thedelatorrereview.com/what-is-the-right-to-erasure-or-right-to-be-forgotten-under-the-gdpr/) — Explains when individuals may require deletion of their personal data and the important exceptions that limit the right.
- [**What Is the “Right to Object” Under the GDPR?** ](https://www.thedelatorrereview.com/what-is-the-right-to-object-under-the-gdpr/)— Examines when individuals may object to processing based on legitimate interests or public task and the absolute right to object to processing for direct marketing.
- [**Controller-to-Processor Transfers: What Article 28 GDPR Requires**](https://www.thedelatorrereview.com/controller-to-processor-transfers-what-article-28-gdpr-requires/) — Explains the GDPR requirements governing relationships between controllers and processors, including the contractual safeguards required by Article 28.
- [**GDPR Records of Processing Activities (ROPAs) Explained: A Practical Guide to Article 30**](https://www.thedelatorrereview.com/gdpr-records-of-processing-activities-ropas-explained-a-practical-guide-to-article-30/) — Explains controller and processor recordkeeping obligations under Article 30 and how a ROPA can serve as a broader privacy-governance and accountability tool.
- [**Data Protection by Design and by Default Under the GDPR: What Article 25 Requires**](https://www.thedelatorrereview.com/data-protection-by-design-and-by-default-under-the-gdpr-what-article-25-requires/) — Explains the obligation to integrate data protection safeguards into products, services, systems, and business processes from the outset and to apply privacy-protective defaults.
- [**The GDPR’s DPIA Requirement: Identifying, Assessing, and Mitigating High-Risk Processing**](https://www.thedelatorrereview.com/data-protection-by-design-and-by-default-under-the-gdpr-what-article-25-requires/) — Explains when a Data Protection Impact Assessment is required, how organizations assess and mitigate risks to individuals, and when prior consultation with a supervisory authority may be necessary.
- [**The GDPR Data Protection Officer (DPO) Explained: When You Need One and What They Do**](https://www.thedelatorrereview.com/the-gdpr-data-protection-officer-dpo-explained-when-you-need-one-and-what-they-do/) — Examines when a DPO must be appointed, the DPO’s responsibilities, and the independence and organizational protections associated with the role.
- [**GDPR Data Security Explained: A Practical Guide to Technical and Organizational Measures**](https://www.thedelatorrereview.com/gdpr-data-security-explained-a-practical-guide-to-technical-and-organizational-measures/) — Reviews the GDPR’s risk-based security requirements and the obligation to implement appropriate technical and organizational measures to protect personal data.
- [**GDPR Data Breaches Explained: Security Incidents, Risk Assessment and Notification Requirements**](https://www.thedelatorrereview.com/gdpr-data-breaches-explained-security-incidents-risk-assessment-and-notification-requirements/) — Explains the GDPR’s personal-data-breach framework, including the 72-hour supervisory-authority notification rule, notification of affected individuals in high-risk cases, and breach record-keeping requirements.
- [**When Can Personal Data Leave the EU? A Practical Guide to GDPR International Transfers**](https://www.thedelatorrereview.com/whencanpersonaldataleavetheeu/) — Explains the GDPR rules governing transfers of personal data outside the EU, including adequacy decisions, appropriate safeguards, and derogations.
- [**GDPR Codes of Conduct: How They Work and Why They Matter**](https://www.thedelatorrereview.com/gdpr-codes-of-conduct-how-they-work-and-why-they-matter/) — Explains how industry and sector-specific codes of conduct can translate GDPR requirements into practical standards and help organizations demonstrate compliance.
- [**GDPR Certifications: Demonstrating Data Protection Compliance**](https://www.thedelatorrereview.com/gdpr-certifications-demonstrating-data-protection-compliance/) — Explains the GDPR certification framework and how approved certification mechanisms can be used to demonstrate compliance with specified data protection requirements.