GDPR and the CCPA: Testimony Before the California Senate Judiciary Committee

A look back at my 2019 testimony before the California Senate Judiciary Committee, explaining the GDPR, its historical foundations and core principles, and how Europe’s approach to data protection compared with California’s newly enacted CCPA.

GDPR and the CCPA: Testimony Before the California Senate Judiciary Committee
ChatGPT generated image from: Fred Morlan Special Collection Photo (California State Capitol in Sacramento) — SDASM Archives

Historical Context

I was invited by Senator Hannah-Beth Jackson, then Chair of the California Senate Judiciary Committee, to testify at the Committee’s March 5, 2019 informational hearing, The State of Data Privacy Protection: Exploring the California Consumer Privacy Act and its European Counterpart. The hearing took place shortly after enactment of the California Consumer Privacy Act (CCPA) and before it became operative. The Legislature was considering additional amendments to the new law and sought to examine the CCPA alongside other regulatory models—particularly the EU General Data Protection Regulation (GDPR)—as it considered how California’s new privacy framework should develop. 

I participated in the panel devoted to comparing the CCPA with its counterparts and examining compliance, where my role was to provide the Committee with an overview of the GDPR and the European approach to data protection. I am sharing my testimony here because it provides both a snapshot of an important moment in the development of California privacy law and an accessible introduction to the historical foundations and core principles of European data protection law. Much has changed in California privacy law since 2019, but the fundamental GDPR concepts discussed in the testimony remain relevant today.


Testimony

Thank you, Senator Jackson and members of this committee, for giving me the opportunity to participate.


My name is Lydia de la Torre, and I am the Privacy Fellow at Santa Clara School of Law, where I co-direct the privacy program and teach comparative privacy law. I am licensed to practice law both in Spain and in California and, prior to joining Santa Clara, I worked in the private sector — both as outside counsel and as an in-house privacy attorney.

I have been asked to use my time to provide a general overview of what the GDPR is.

What is the GDPR?

GDPR stands for General Data Protection Regulation, and it is one of three laws that implement the right to data protection in the European Union (EU). The other two (1) are rarely discussed in the United States because they apply to the public sector and, therefore, do not affect U.S. organizations.

In the EU, the right to data protection is a fundamental right enshrined in Article 8 of the Charter of Fundamental Rights, which is the EU’s functional equivalent to the U.S. Bill of Rights. In addition, the constitutions of some EU countries provide for a right to data protection. For example, Article 18.4 of the Spanish Constitution grants Spaniards a right to data protection (2).

In addition to having a right to data protection, Europeans also have a right to privacy. The right to privacy is protected under Article 7 of the Charter and is recognized by most, if not all, Member State constitutions. The only area of privacy regulated at the EU level is communications privacy. In 2002, the e-Privacy Directive (3) imposed restrictions on the collection, access, and use of communications data, and mandated certain security measures. It also established consent rules for direct marketing and is, in that sense, the EU counterpart to the U.S. CAN-SPAM Act. The e-Privacy Directive was nicknamed the “Cookie Directive” because it led to the implementation of so-called “cookie walls” on EU websites (4).

A helpful analogy to understand the right to data protection in Europe is this: in the same way that U.S. citizens have a constitutional right to bear arms — distinct from but connected to their right to self-defense — Europeans have a right to data protection, which is distinct from yet connected to their right to privacy.

Historical context

The origin of the right to data protection can be traced back to the rise of automated data processing in the 1960s and 1970s. At the time, the virtues and risks of what we now call computers were debated on both sides of the Atlantic. In the United States, the consensus was that no overarching new regulation was needed. Europeans came to the opposite conclusion and decided to enact a new type of law regulating how computers are allowed to “think” about humans. The original name given to this new legal field was “protection of individuals with regard to automated processing of personal data.” This name was clearly too long and was eventually shortened to Data Protection Law.

The Council of Europe (an international organization to which all EU countries belong) played a key role in developing data protection law. In 1973 and 1974, it issued two influential resolutions that laid down the data-processing principles embedded today in the GDPR. Most importantly, on January 28, 1981, the Council opened for signature the Convention for the Protection of Individuals with Regard to Automated Processing of Personal Data (known as Convention 108). This convention is the seed from which the right to data protection sprouted, and it remains to this day the only binding international agreement in the field of data protection law. Incidentally, it is the reason why Europeans celebrate Data Protection Day annually on January 28.

Tenets of EU data protection law

The first pan-European data protection law was enacted in 1995 (5) and remained in effect until it was repealed by the GDPR in 2016. Its framework was built on four core tenets that have proven strong enough to drive effective compliance yet flexible enough to adapt to the ever-changing nature of technology. These tenets were not changed by the GDPR.

I will briefly discuss them and offer correlations to the CCPA.

FIRST TENET: Technology must be built to serve humankind

In the words of Apple’s CEO: “Technology is capable of doing great things. But it doesn’t want to do great things. It doesn’t want anything. That part takes all of us.” (6)

The overarching goal of data protection law, as described in Recital 4 of the GDPR, is to ensure that technology is designed “to serve mankind.”

To prevent unethical uses of technology, data protection law distinguishes between permissible and non-permissible purposes. EU law identifies six lawful bases that constitute the universe of what is permissible and outlaws the use of personal data for any purpose falling outside those bases. It could be said that, under the GDPR, one is ‘guilty’ of unlawful processing until a lawful basis is identified.

Europe’s history likely explains this restrictive approach. Although lawmakers saw technology’s potential for good, the question of how the Holocaust might have looked if a database tracking citizens’ whereabouts and religion had existed was probably not far from their minds.

The CCPA does not adopt the GDPR’s restrictive general rule but does incorporate the idea of purpose limitation. Specifically, the CCPA subjects the sharing of personal information for certain “commercial purposes” to a right to opt out for adults and a right to opt in for minors. In contrast to the GDPR (which does not define the conduct it restricts), the CCPA explicitly defines the conduct (“data sale”) it restricts.

SECOND TENET: Factual control = accountability

Under EU data protection law, accountability for data handling is directly proportional to factual control. Any entity that “alone or jointly with others determines the purposes and means of processing personal data” is a controller. Entities that act “on behalf of” controllers are processors. Because Europeans see data protection as a fundamental right, very few organizations are exempt from the GDPR. By limiting exemptions and equating control with accountability, the GDPR effectively creates an unbreakable chain of custody over personal data.

The CCPA ties control to accountability by incorporating the concept of “controller” into its definition of “business,” and the concept of “processor” into its definition of “service provider.” However, the CCPA applies only to entities meeting certain thresholds, meaning significant amounts of personal information fall outside its scope. Thus, the chain of custody can be interrupted — but, since the CCPA equates control with accountability, the chain will not break entirely. As data changes hands, whenever an entity that meets the CCPA thresholds gains effective control, its data practices and those of its service providers must comply with the law. For example, a data broker meeting those thresholds is subject to the CCPA, even if it collects data exclusively from sources not covered by the Act and has no direct relationship with the individuals concerned.

THIRD TENET: If you can connect it, we will regulate it

The line between “private and sensitive” and “public and harmless” is blurry today. Advances in technology enable identification of individuals based on data that seems random, and make it possible to derive sensitive information from mundane data sets. For example, researchers have found that 95% of cellphone users can be uniquely identified using only four spatio-temporal points (7). This fluidity has hamstrung legal frameworks that limit their scope to inherently “private” or “sensitive” data.

European data protection law restricts the processing of personal data, defined as “information relating to an identified or identifiable natural person.” Though short, this definition is interpreted broadly by courts and data protection authorities.

Information need not be private or confidential to be subject to the GDPR. Some of the most public facts about us — including our names — are unquestionably personal. Proof of a special interest to prevent dissemination or misuse is unnecessary, and establishing a “reasonable expectation of privacy” is not required. Therefore, publicly available data is subject to the GDPR so long as it is personal in nature.

Similarly, data need not be sensitive. Article 9 of the GDPR places additional restrictions on processing information that has historically been a vector for discrimination, such as race, religion, political affiliation, or sexual orientation (so-called “special categories”). However, there is no minimum threshold of sensitivity below which the GDPR does not apply.

The definition of personal information under the CCPA is more comprehensive than any existing definition under California law. It includes data elements that, in and of themselves, are neither private nor sensitive. Some argue that the CCPA regulates data not covered under the GDPR. I personally cannot imagine how any interpretation of the CCPA could yield that outcome, especially when it excludes data types (such as anonymized and aggregated data) that are also excluded from the GDPR.

FOURTH TENET: Transparency is the path to fairness

A key goal of data protection law has always been to enhance the transparency of data processing. Transparency is viewed as a prerequisite for fairness because, in many ways, compliance with data protection law is a “black box.”
From granting individuals the right to be informed and the right of access, to requiring the creation of data management policies, imposing record-keeping obligations, mandating Data Protection Officers, and enabling a private right of action, many GDPR provisions exist to ensure transparency.

The CCPA goes further than any existing U.S. federal or state law in including transparency-enhancing provisions and, most notably, gives Californians a right to access their personal information. However, it does not go as far as the GDPR.

As a final point, in my experience, protecting personal data requires (1) appointing independent, well-trained professionals to managerial positions, and (2) establishing mechanisms that effectively protect them when they raise issues internally. The CCPA does not specifically require appointing compliance officers, and California law offers no meaningful protections to privacy professionals — despite their function as embedded regulatory enforcers, sometimes in unfriendly environments. Empowering and protecting these professionals would, in my view, go a long way toward ensuring effective privacy protection for California residents.

Conclusion

In conclusion, in addition to having a right to privacy, Europeans also have a right to data protection. The GDPR is one of the EU’s three data protection laws. Its stated goal is to ensure that technology is built to serve mankind and, to this end, it allows the use of personal data only for ethical purposes, creates an unbreakable chain of custody by equating accountability with factual control, and includes many transparency-enhancing provisions.

The CCPA represents an innovative approach to privacy enforcement in California and, although not modeled after the GDPR, it incorporates several elements that have formed the core compliance structure of European data protection law since 1995.

I again thank the Chair and members of the committee for the opportunity to participate in this hearing, and I look forward to your questions.

Endnotes:

  1. Regulation (EU) 2018/1725, governing the processing of personal data by EU institutions, bodies, offices and agencies, and Directive (EU) 2016/680 (the Law Enforcement Directive), governing the processing of personal data by competent authorities for law-enforcement purposes.
  2. Article 18.4 of the Constitution of Spain states:
“The law shall restrict the use of data processing in order to guarantee the honour and personal and family privacy of citizens and the full exercise of their rights.”
NOTE: In 1992 (that is to say, three years before the EU 1995 data protection directive was enacted) Spain enacted its first data protection law: The organic law 5/1992, of October 29, regulating the processing of personal data through automated means (LORTAD).
  1. Directive 2002/58/EC (ePrivacy Directive), as amended by Directive 2009/136/EC
  2. Cookie walls are ‘pop-ups’ placed on a website to inform users about the website’s online tracking policies.
  3. Directive 95/46/EC
  4. This remarks were provided October 24th of last year at the International Conference of Data Protection & Privacy Commissioners in Brussels, the CEO of Apple was a keynote speaker
  5. Unique in the Crowd: The privacy bounds of human mobility” 2013 Scientific Reports article by Yves-Alexandre de MontjoyeCésar A. HidalgoMichel Verleysen & Vincent D. Blondel

Additional Resources:

California Senate Judiciary Committee Hearing Materials

For readers interested in exploring the concepts discussed in this testimony in greater depth:

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe