The four frameworks most useful to compare are GDPR, California’s CCPA as amended by CPRA, HIPAA, and PCI DSS. They are not four equivalent certifications: GDPR and CCPA/CPRA are privacy laws, HIPAA is a U.S. law implemented through rules, and PCI DSS is an industry security standard. Which ones matter to an organization depends on where it operates, its role, the data it handles, and whether it handles payment-card data.
How the four frameworks differ
| Framework | Jurisdiction or program | Who may be in scope | Data and main purpose | How applicability is determined |
|---|---|---|---|---|
| GDPR | European Union data-protection law | Organizations whose processing falls within the regulation’s scope; exact reach depends on its text and circumstances. | Personal data; governs data protection, including collection, use, transmission, and security. | Assess the regulation’s territorial reach, the organization’s role, and the processing involved. |
| CCPA, as amended by CPRA | California privacy law | Businesses meeting the law’s definitions and thresholds; not every business is covered. | California residents’ personal information; establishes privacy rights and related business obligations. | Check statutory definitions and thresholds, along with the organization’s activities. |
| HIPAA | U.S. federal law implemented through rules | Covered entities—health plans, health care clearinghouses, and certain health care providers—and their business associates. | Protected health information; the Security Rule specifically addresses electronic protected health information (ePHI). | Determine whether the organization is a covered entity or business associate and whether the relevant information is protected health information. |
| PCI DSS | Payment-card industry security standard | Entities that store, process, or transmit payment account data, as determined through the relevant payment compliance program. | Payment account data; sets technical and operational security requirements. | Payment brands, acquirers, or other organizations managing compliance programs determine who must comply and what validation is required. |
The table describes different triggers, not alternatives. An organization can fall under more than one framework—for example, because it handles different categories of data or operates across jurisdictions. Meeting one framework does not automatically satisfy another.
What each framework covers
GDPR: personal-data protection in the EU context
The General Data Protection Regulation (GDPR) concerns personal data and data protection. NIST’s manufacturer overview describes it as governing the collection, use, transmission, and security of data collected from EU residents. That overview is a high-level explanation, not a substitute for the regulation. Territorial reach, lawful bases, exceptions, and specific duties depend on the legal text and the facts of the processing, so a business should not infer its obligations from a short summary alone.
CCPA/CPRA: California residents’ privacy rights
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents rights that include asking what personal information a business holds and how it is used, requesting deletion, opting out of sale or sharing, correcting inaccurate information, and limiting certain uses or disclosures of sensitive personal information. The California Attorney General’s FAQ says the CPRA statutory amendments took effect January 1, 2023, and updated implementing regulations became effective March 29, 2023.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Those dates do not mean every business is covered. Applicability depends on statutory definitions and thresholds, which an organization must assess against its own circumstances. The Attorney General’s FAQ also notes that employment-related and business-to-business exemptions expired at the end of 2022.
HIPAA: protected health information and ePHI safeguards
HIPAA’s Privacy, Security, and Breach Notification Rules address protected health information in different ways. The Security Rule applies to covered entities and business associates and concerns ePHI. HHS describes its safeguards as administrative, physical, and technical measures intended to protect the confidentiality, integrity, and availability of that information.
Health-related information is not automatically covered by HIPAA just because it concerns health, and a health app is not automatically subject to the law. The relevant questions include whether the organization is a covered entity or business associate and whether the information is protected health information in the circumstances at issue.
PCI DSS: protecting payment account data
The PCI Data Security Standard (PCI DSS) is a baseline of technical and operational requirements for environments that store, process, or transmit payment account data. Its focus is payment security rather than general consumer privacy. PCI Security Standards Council (PCI SSC) materials describe the standard’s requirements, but payment brands, acquirers, or other organizations administering compliance programs determine which entities must comply or validate compliance. The Council does not impose one identical validation process on every merchant.
Free tools Windows power users keep installed
One-click scans. No signup required.
What changed around 2023—and what came later
- California: CPRA statutory amendments took effect January 1, 2023; updated implementing regulations took effect March 29, 2023.
- PCI DSS: PCI SSC published version 4.0 on March 31, 2022. Its announcement said version 3.2.1 would remain active until March 31, 2024, so the transition had not ended during 2023. Changes highlighted by PCI SSC included broader multi-factor authentication expectations for access into the cardholder data environment, updated network-security-control terminology, and flexibility through targeted risk analyses. PCI SSC’s current materials are in the v4.x family; consult the current official standard and the relevant payment program for present-day validation advice.
- HIPAA: HHS’s Security Rule page records a proposal to strengthen the rule dated January 6, 2025. A proposal is not automatically a requirement in force. NIST Special Publication 800-66 Revision 2, published in February 2024, is an implementation resource, not a replacement for the regulation.
How to work out which framework may apply
- Map where you operate and whom you serve. Identify the jurisdictions connected to your organization and its data processing. For GDPR and CCPA/CPRA, geography is a starting point, but legal scope depends on the applicable law and facts.
- Identify your role. Check whether you act as a business handling California residents’ personal information, a HIPAA covered entity or business associate, or an entity in a payment program. A vendor’s role can differ from its customer’s.
- Classify the data. Separate personal information, protected health information or ePHI, and payment account data. An organization may handle more than one category, each with different obligations.
- Check the governing authority or program. Use the applicable law and regulator guidance for privacy and health obligations, and ask the relevant payment brand, acquirer, or compliance-program contact about PCI DSS scope and validation.
- Get a fact-specific assessment. For a consequential decision, have qualified privacy or legal counsel, a HIPAA security professional, or a PCI assessor review the organization’s activities. A general explainer cannot determine legal applicability for a particular business.
Implementation is ongoing, not a one-time certificate
For HIPAA, HHS describes compliance as a continuing process: conduct a risk analysis, select reasonable and appropriate safeguards, document policies and procedures, and evaluate them periodically. The appropriate measures depend on the organization’s context. NIST SP 800-66 Rev. 2 can help translate Security Rule concepts into implementation work, but the legal rule remains controlling.
PCI DSS likewise concerns operational and technical controls in the payment-data environment; use the current PCI SSC materials and the requirements of the applicable payment program rather than relying on a historical version-transition summary. For privacy laws, start from the rights and duties that apply to the specific processing and organization rather than treating a security checklist as proof of compliance.
Quick Recap
Rank #4
Primary guidance to consult
- GDPR: the regulation’s text and relevant EU data-protection authority guidance. NIST’s manufacturer overview is useful for orientation, not legal interpretation.
- CCPA/CPRA: the California Attorney General’s FAQ and applicable California law and regulations.
- HIPAA: HHS guidance on the Privacy, Security, and Breach Notification Rules; NIST SP 800-66 Rev. 2 is supplementary implementation guidance.
- PCI DSS: PCI SSC’s current standard and Quick Reference Guide, plus the instructions of the payment program responsible for the organization’s compliance and validation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

