GDPR vs CCPA ADMT: what they share and how they differ
GDPR and CCPA ADMT share 5 of 24 control themes and 4 checks. 100% of CCPA ADMT requirements can be proven with checks GDPR already uses, 40% the other way round.
In force
GDPR
How to make AI compliant with the GDPR
10 requirementsNext Jan 2027
Phasing in
CCPA ADMT
How to comply with the CCPA automated decision-making rules
4 requirementsNext Jan 1, 2027
5/24shared control themes
4shared checks
100%of CCPA ADMT requirements covered by GDPR evidence
40%of GDPR requirements covered by CCPA ADMT evidence
At a glance
| GDPR | CCPA ADMT | |
|---|---|---|
| Jurisdiction | European Union | California |
| Kind | Regulation | Implementing rules |
| Status | In force | Phasing in |
| Binding | Yes same | Yes same |
| Object analysed | Data processing | Automated decision |
| Scope | Controllers and processors. | CCPA-covered businesses using ADMT for significant decisions. |
| Territorial reach | EU establishment, or targeting / monitoring people in the EU. | California resident consumers. |
| Penalties | Up to €20M or 4% of worldwide turnover. | $2,663 to $7,988 per violation (indexed amounts). |
| Qualification axes | Automated decision (Art. 22), DPIA required (Art. 35) | ADMT for a significant decision |
| Roles | Controller, Processor | Business |
| Requirements | 10 | 4 |
| Next milestone | Jan 2027, Possible adoption of the Omnibus amendments | Jan 1, 2027, ADMT compliance required |
Theme by theme
requirements per theme
GDPRCCPA ADMT
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
4
| Code | Check | Requirements GDPR | Requirements CCPA ADMT |
|---|---|---|---|
| VER-029-D-01 | Affected persons informed of the use of the AI system | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | ||
| VER-019-D-02 | DPIA carried out in accordance with GDPR Art. 35 | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
GDPR
6
GDPR-01
GDPR-04
GDPR-05
Record of processing activities Art. 30
GDPR-07
Security of processing Art. 32
GDPR-08
Breach notification within 72 hours Art. 33, 34
GDPR-09
CCPA ADMT
0
None: every requirement shares at least one check.
Timelines
PastSet in the textPotentialTo verify
Apr 27, 2016GDPR · Adoption
May 25, 2018GDPR · Application date
Dec 17, 2024GDPR · EDPB Opinion 28/2024 on AI models
Sep 23, 2025CCPA ADMT · Approved by OAL
Nov 19, 2025GDPR · Digital Omnibus: legitimate interest for AI training, personal data definition
Jan 1, 2026CCPA ADMT · Effective date
Jan 1, 2027CCPA ADMT · ADMT compliance required
Jan 2027GDPR · Possible adoption of the Omnibus amendments
Apr 1, 2028CCPA ADMT · First risk-assessment attestations
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.