OpenDD
← All articles

Privacy Due Diligence: GDPR & CCPA Signals

Privacy · Updated July 2026

A company's privacy practices used to be a footnote in diligence. They aren't anymore — regulators have handed out fines in the hundreds of millions, and a target's sloppy data handling can become the acquirer's liability overnight. The good news is that a company tells you a lot about its privacy posture in documents that are, by law, public: its privacy policy chief among them.

The privacy policy is a disclosure, so read it like one

A privacy policy isn't marketing; under GDPR and CCPA it's a legally-required disclosure of what data a company collects, why, on what legal basis, and who it shares with. Read it the way you'd read a risk factor. Vague, boilerplate policies that could belong to any company are a signal in themselves — they often mean privacy hasn't been thought through, not that there's nothing to disclose.

GDPR: the signals that matter

For any company touching EU personal data, start with the substance the GDPR requires. The policy should state a clear legal basis for each kind of processing — consent, legitimate interest, contractual necessity, or one of the other Article 6 grounds — rather than gesturing vaguely at "your consent" for everything.

Legal basis matters because it dictates what a company may do. A firm relying on legitimate interest, for instance, must offer a genuine right to object; when a policy lists no bases at all, it usually means no one mapped the processing to the law.

Next, look for a working mechanism for data-subject rights: access, deletion, correction, portability, and objection. A named contact, a form, or a request address signals the company expects to field these; rights granted on paper with no route to exercise them are a gap worth noting.

International transfers: where the data actually goes

Once EU personal data leaves the EEA — most often to U.S. servers or vendors — the GDPR requires a lawful transfer mechanism. The common ones are the EU-U.S. Data Privacy Framework (DPF) for certified U.S. recipients and Standard Contractual Clauses (SCCs) for everyone else.

A policy that names its transfer mechanism, and lists the countries or providers involved, is telling you the company has thought this through. Silence on transfers, for a company with EU users and sub-processors abroad, is a red flag — the transfers are almost certainly happening whether documented or not. If the company publishes a sub-processor list, cross-check it against the stated transfer mechanism.

Retention, minimization and the DPO

Two quieter GDPR signals are retention and accountability. The policy should describe how long data is kept and on what basis, rather than an open-ended "as long as necessary" — indefinite retention is both a compliance weakness and a breach-exposure problem.

On accountability, check whether the company names a Data Protection Officer or an EU representative where one is required, and gives a real way to reach them. A staffed privacy function signals the program has an owner; a generic "contact us" often means it does not.

CCPA/CPRA: the California layer

For California consumers, the questions shift slightly. Look for whether the company honors the rights to know, delete and correct, and whether it offers a clear "Do Not Sell or Share My Personal Information" link where its data practices require one. The CCPA, as amended by the CPRA, treats "sharing" for cross-context behavioral advertising much like a sale, so a company running ad trackers often owes users this control even if it insists it never "sells" data.

Sensitive personal information gets its own layer under the CPRA — categories like precise geolocation, health data, and account credentials, which consumers can ask a business to limit. A California-facing policy that never addresses sensitive data, opt-outs, or the categories collected and disclosed is thin against the statute.

The cookie banner tells on the company

One of the fastest tells is the consent experience. A compliant banner lets users refuse non-essential cookies as easily as they accept them, and it doesn't drop tracking cookies before consent. A banner with only an "Accept" button, or one that loads trackers on arrival, reveals a gap between the policy's promises and the site's behavior — and that gap is exactly what regulators look for.

You can verify this yourself in a minute. Open the site in a private window, watch what loads before you click, and check whether "reject all" is a real, equally-prominent option. Under GDPR consent must be freely given; under CCPA the same banner often doubles as the opt-out signal, so a broken banner is a defect in both regimes at once.

Children's data raises the stakes

If a company knowingly collects data from children, the diligence bar rises sharply. In the U.S. the COPPA rule governs data from users under 13, and the GDPR sets its own thresholds for a child's consent, with member states fixing the exact age between 13 and 16.

A policy should still say whether the service is intended for children and how it handles data it learns belongs to one. Services that plausibly reach minors but stay silent carry real enforcement risk. For a fuller picture, our wider due-diligence tools score privacy alongside security and vendor risk.

Score a privacy program. OpenDD's Privacy Due Diligence module builds a GDPR/CCPA scorecard from a company's own disclosures — policy, legal bases, rights, retention, transfers, DPO and cookie consent. Run a privacy check →

Disclosure isn't the same as practice

A polished privacy policy proves a company can write one, not that it lives by it — the real test is whether stated practices match actual behavior, which needs more than a document review. Use the public disclosures to score the posture and flag the gaps and contradictions, then verify the high-stakes items directly. This is general information, not legal advice; privacy law is jurisdiction-specific and evolving.

Related guides

SOC 2 vs ISO 27001 → Third-Party & Vendor Due Diligence → AI Governance Due Diligence →