GDPR and CCPA in Brief

Privacy law follows the customer, not the server: a bookshop in Malaysia that sells to readers in Germany and California answers to three regimes at once.

Three privacy regimes a BookNest data engineer meets (as of October 2026)
Law In force Applies to Maximum penalty
GDPR (EU) 25 May 2018 People in the EU EUR 20M or 4% turnover
CCPA/CPRA (California) 2020; CPRA 2023 Firms over $26.6M revenue $7,988 per violation
PDPA (Malaysia) 2013; amended 2024 Commercial processing Fine, prison or both

The GDPR gives rights of access, erasure, portability and objection; its fine is whichever figure is higher. The CCPA gives rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive data; $7,988 applies to intentional violations, $2,663 to others. Malaysia's 2024 amendment came into force during 2025, adding mandatory data protection officers and breach notification from 1 June 2025, and made biometric data sensitive.

For engineers, all three mean the same habits: tag where personal data lives, copy only what a purpose needs (data minimization), enforce retention, and be able to delete one person's records (Retention and GDPR Deletion).