DPDP Rules status: compliance window active. Read the update

Skip to content
Going Global · US

DPDP vs US Privacy Laws (CCPA/CPRA)

No federal US privacy law yet. Compliance for Indian businesses serving US users is a state-by-state patchwork — with real overlap to DPDP on notice, access, and deletion.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

As of the last verification of this page, there is no federal privacy law in the United States. The California Consumer Privacy Act (CCPA) and its amendment CPRA apply to businesses that meet certain thresholds and process California residents' data. Those thresholds include:

  • Revenue.
  • User volume.
  • Data volume.

At least 19 other US states have enacted similar laws.

When it applies to you

You are in scope if you offer goods or services to US residents, or otherwise process their data. You must also meet the applicability thresholds of the specific state law. Thresholds differ across states. So check applicability state by state — it's not a single yes / no.

Overlap with India

  • Both require a privacy notice.
  • Both provide data-subject access rights.
  • Both provide a deletion mechanism.

Where the vocabulary differs

CCPA talks about "consumer", "business", and "sale of personal information". DPDP talks about "Data Principal" and "Data Fiduciary". The concepts overlap a lot. But if you map a control to one vocabulary, check it against the other too.

If you have both US and Indian users

You must satisfy both frameworks on their own. US compliance does not substitute for DPDP. DPDP does not substitute for US state laws either.

In plain English: the US side is a moving patchwork. We have not confirmed an official list of states yet. Treat "US privacy compliance" as a state-by-state exercise, not a single obligation.

Quick self-check

Check your readiness

Serving users in more than one jurisdiction? Run the readiness checklist to see your baseline DPDP coverage before adding foreign-law obligations on top.

Run it now