GDPR vs CCPA ADMT: what they share and how they differ

GDPR and CCPA ADMT share 5 of 24 control themes and 4 checks. 100% of CCPA ADMT requirements can be proven with checks GDPR already uses, 40% the other way round.

EURegulationIn force

GDPR

How to make AI compliant with the GDPR

10 requirementsNext Jan 2027
CAImplementing rulesPhasing in

CCPA ADMT

How to comply with the CCPA automated decision-making rules

4 requirementsNext Jan 1, 2027
5/24shared control themes
4shared checks
100%of CCPA ADMT requirements covered by GDPR evidence
40%of GDPR requirements covered by CCPA ADMT evidence

At a glance

GDPR CCPA ADMT
JurisdictionEuropean UnionCalifornia
KindRegulationImplementing rules
StatusIn forcePhasing in
BindingYes sameYes same
Object analysedData processingAutomated decision
ScopeControllers and processors.CCPA-covered businesses using ADMT for significant decisions.
Territorial reachEU establishment, or targeting / monitoring people in the EU.California resident consumers.
PenaltiesUp to €20M or 4% of worldwide turnover.$2,663 to $7,988 per violation (indexed amounts).
Qualification axesAutomated decision (Art. 22), DPIA required (Art. 35)ADMT for a significant decision
RolesController, ProcessorBusiness
Requirements104
Next milestoneJan 2027, Possible adoption of the Omnibus amendmentsJan 1, 2027, ADMT compliance required

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

4

CodeCheckRequirements GDPRRequirements CCPA ADMT
VER-029-D-01Affected persons informed of the use of the AI system
CHK-BR-CONTESTProcedure to contest a decision and obtain human review published
VER-019-D-02DPIA carried out in accordance with GDPR Art. 35
VER-033-D-03Explanations provided on request within a reasonable timeframe

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

CCPA ADMT

0

None: every requirement shares at least one check.

Timelines

PastSet in the textPotentialTo verify
Apr 27, 2016GDPR · Adoption
May 25, 2018GDPR · Application date
Dec 17, 2024GDPR · EDPB Opinion 28/2024 on AI models
Sep 23, 2025CCPA ADMT · Approved by OAL
Nov 19, 2025GDPR · Digital Omnibus: legitimate interest for AI training, personal data definition
Jan 1, 2026CCPA ADMT · Effective date
Jan 1, 2027CCPA ADMT · ADMT compliance required
Jan 2027GDPR · Possible adoption of the Omnibus amendments
Apr 1, 2028CCPA ADMT · First risk-assessment attestations

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo