CRO
CHIEF
REPUTATION
OFFICERS
Digital Privacy11 min read

GDPR and Reputation Management: A Practitioner's Guide for Non-EU Companies

Target: “GDPR reputation management

When California passed the California Consumer Privacy Act in 2018, the inevitable press framing was that America finally had its own GDPR. The comparison was convenient shorthand. It was also misleading in ways that matter directly to anyone advising clients on digital privacy.

For practitioners advising clients on digital privacy, the CCPA-versus-GDPR distinction has direct practical consequences. A client in Munich and a client in Miami facing the same data broker exposure problem have substantially different legal tools available to them. Understanding why — and communicating it clearly — is the difference between a realistic client brief and one that overpromises what opt-outs and deletion requests can achieve.

GDPR: A Rights Framework With Enforcement Behind It

The General Data Protection Regulation, in force across the EU since May 2018, is built on the principle that individuals have fundamental rights over their personal data. Organizations that process personal data about EU residents must have a lawful basis for doing so — consent, legitimate interest, contractual necessity, legal obligation, vital interests, or public task — and must be prepared to demonstrate that basis if challenged. The default position is that personal data collection is not permitted unless justified. Organizations must prove the justification.

The rights that matter most for reputation and privacy work are the right to erasure (Article 17), commonly called the right to be forgotten, and the right to object (Article 21). The right to erasure allows individuals to request deletion of their personal data where it is no longer necessary for the purpose for which it was collected, where consent has been withdrawn, or where it was processed unlawfully. The right to object allows individuals to object to processing based on legitimate interests, at which point the organization must demonstrate compelling legitimate grounds that override the individual's interests. If it cannot, processing must stop.

What gives these rights real weight is enforcement. Data Protection Authorities in each EU member state can investigate complaints and impose fines. Under GDPR, fines can reach four percent of global annual revenue or €20 million, whichever is higher. These are not theoretical maximums that regulators never actually use. Meta has received multi-billion-euro fines under GDPR. Google, Amazon, and H&M have received nine-figure fines. Organizations know GDPR compliance is enforced, which means deletion requests carry regulatory weight that opt-out requests under US law generally do not.

Extraterritorial Reach

GDPR applies to any organization that processes personal data of individuals located in the EU, regardless of where the organization is based. A US data broker that holds and processes information about EU residents is subject to GDPR. Many are not compliant. The enforceability against offshore entities is more complex, but the legal obligation exists.

CCPA: Opt-Out Rights Inside a Default-On System

The California Consumer Privacy Act, effective January 2020 and amended by the California Privacy Rights Act in 2023, gave California residents meaningful new rights over their personal data. Compared to what existed in US law before it, CCPA was a significant step forward. Compared to GDPR, it operates on fundamentally different premises.

CCPA gives California residents the right to know what data a business holds, the right to delete it, the right to opt out of its sale or sharing, and the right to limit the use of sensitive personal information. These are real rights with legal backing. But the structural architecture matters.

CCPA is an opt-out system. Data collection and use is permitted by default. The individual must take action to limit it. GDPR inverts this: data collection requires justification upfront. An EU resident challenging data processing can point to the absence of lawful basis. A US resident challenging the same processing under CCPA can only ask the company to stop — and must do so site by site, company by company, with no ability to invoke a lawful basis requirement because US law does not impose one.

The Core Structural Difference

GDPR is a floor. Organizations must justify processing personal data before they do it, and individuals can challenge that justification. CCPA is an opt-out system: collection is permitted by default, and individuals must take action to limit it after the fact.

The enforcement gap

CCPA enforcement sits with the California Attorney General and the California Privacy Protection Agency. Resources are limited relative to the scale of the industry being regulated. Individual consumers have a private right of action only for data breaches, not for general CCPA violations — meaning that a company that ignores a deletion request has limited exposure to individual legal action. The practical result is that CCPA compliance is uneven, enforcement is selective, and a deletion request that carries real regulatory weight under GDPR carries significantly less under CCPA. Many data brokers comply with CCPA requests because the reputational cost of not doing so outweighs the marginal cost of honoring them, not because enforcement is swift or certain.

What This Means for Clients

US-based clients

A US client facing data exposure from people search sites and data brokers does not have a meaningful federal privacy law behind them. CCPA applies only to California residents and only to businesses meeting specific revenue or data-processing thresholds. Other states have enacted their own privacy laws — Virginia, Colorado, Connecticut, and others — but coverage is patchwork and enforcement mechanisms vary. The opt-out process for US clients works because most major data brokers have chosen to honor requests rather than face the reputational cost of refusing, not because the legal compulsion is strong. The practical ceiling is the repopulation problem: upstream data that continuously regenerates listings on sites where opt-outs have been submitted.

EU-based clients

An EU client has substantially stronger tools. A GDPR deletion request to a data broker or search engine carries regulatory weight. Google's Right to Be Forgotten process, established following the 2014 Court of Justice of the European Union ruling in Google Spain v. AEPD, allows EU residents to request the removal of search results for their name where those results are inadequate, irrelevant, or no longer relevant. Google has processed hundreds of thousands of these requests. Not all succeed — Google balances privacy interests against public interest and the requester's public role — but the mechanism is real, used, and produces results that equivalent requests in the US cannot.

For EU clients facing data broker exposure specifically, the GDPR lawful basis framework is the lever. A data broker that cannot articulate a lawful basis for processing an EU resident's personal data is not merely being asked politely to stop — it is processing data unlawfully and exposing itself to regulatory action. Many international data brokers have updated their processes to handle EU deletion requests more rigorously than US requests precisely because the regulatory exposure is different.

Cross-jurisdiction clients

Executives and public figures operating across the US and EU often have data exposure in both jurisdictions. The strategy for a client with EU presence should explicitly separate the two: EU-based data exposure can be addressed with GDPR requests that carry regulatory weight, while US-based exposure requires the standard opt-out process with its attendant limitations. Conflating the two — assuming that a GDPR deletion request to a US-based data broker will be honored with the same urgency as one sent to an EU-regulated entity — leads to unrealistic expectations about timeline and outcome.

Practitioners advising cross-jurisdiction clients should document which data broker entities are EU-regulated and which are not. The same data broker may operate under different legal entities in different markets with different compliance obligations. The entity that received the request matters as much as the request itself.

The Bottom Line

CCPA gave US consumers opt-out rights and disclosure entitlements inside a system that still permits data collection by default. GDPR gave EU residents a rights framework with the presumption reversed and enforcement behind it. The gap between these two regimes is not a technicality. It is the practical difference between asking a data broker to stop and having legal grounds to compel it. Practitioners who treat the two frameworks as roughly equivalent will routinely overpromise what they can achieve for US clients and underutilize the tools available for EU ones.

Related Topics