data privacy GDPR vs CCPA

GDPR vs CCPA : A Practical Guide to Data Privacy Compliance

Data privacy rules continue to reshape how organizations manage personal information. Navigating GDPR vs CCPA requirements is essential for businesses operating in today's global digital economy.

 

GDPR vs CCPA A Practical Guide to Global Data Privacy Compliance

The General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) are the two most consequential data privacy laws affecting US businesses today. GDPR governs how organizations handle personal data of EU residents. CCPA gives California consumers the right to know, access, and limit how their data is used. Despite different origins, both laws impose real compliance obligations on American companies — and ignoring either carries significant legal and financial risk. This guide breaks down how each law works, where they differ, and what your organization needs to do to comply with both in 2026.

What Is GDPR and Which US Companies Does It Apply To?

GDPR applies to any organization that collects or processes personal data from individuals in the European Union—regardless of where that business is located. That scope catches most US companies off guard.

The regulation came into force in May 2018 and replaced a fragmented set of national data protection laws across EU member states. Personal data under GDPR is defined broadly: names, email addresses, IP addresses, location data, cookie identifiers, and any information that can directly or indirectly identify a living individual. If your website, app, or e-commerce store attracts EU users and collects any of that data, GDPR applies to you.

Every data collection activity must have a lawful basis—consent, contractual necessity, legal obligation, legitimate interest, vital interests, or public task. Data cannot be collected simply because it might be useful later.

Key obligations include:

  • Obtaining explicit consent before processing where consent is the legal basis

  • Publishing a clear privacy notice explaining what data is collected, why, and how long it is retained

  • Responding to individual requests to access, correct, port, or delete personal data

  • Reporting qualifying data breaches to regulators within 72 hours of discovery

Penalties reach up to €20 million or 4% of annual global turnover—whichever is higher. In 2023, Meta was fined €1.2 billion by Ireland's Data Protection Commission for unlawful transfers of EU user data to the United States—the largest GDPR penalty on record. That figure alone illustrates the enforcement risk US companies now face.

What Is CCPA and Does It Apply to Your Business?

CCPA applies to for-profit businesses that collect data from California residents and meet at least one specific revenue or data-volume threshold—not every business that touches California user data.

The law took effect in January 2020 and was strengthened significantly by the California Privacy Rights Act (CPRA) in January 2023. The CPRA established the California Privacy Protection Agency (CPPA)—the first dedicated state privacy regulator in US history—and expanded consumer rights beyond the original CCPA framework.

A business falls under CCPA if it meets any one of these thresholds:

  • Annual gross revenue exceeding $25 million

  • Annual purchase, sale, or receipt of personal information from 100,000 or more California consumers or households

  • Deriving 50% or more of annual revenue from selling or sharing personal information

California residents can request to know what data is collected, demand deletion, opt out of data sales or sharing, correct inaccurate data, and limit the use of sensitive personal information—a right added under the CPRA. Businesses cannot retaliate against consumers who exercise any of these rights.

Civil penalties are $2,500 per unintentional violation and $7,500 per intentional violation—calculated per consumer per incident. In 2022, Sephora became the first company to settle a CCPA enforcement action, paying $1.2 million for failing to disclose data sales and ignoring opt-out signals. CCPA also provides consumers a private right of action when unencrypted personal data is exposed due to a business's failure to maintain reasonable security practices.

Where Do GDPR and CCPA Fundamentally Differ?

The core difference comes down to consent philosophy: GDPR requires opt-in before data collection; CCPA allows data collection by default and gives consumers the right to opt out after the fact.

That distinction shapes everything else about how each law operates. Here is where the two frameworks diverge most significantly.

Consent model. GDPR requires affirmative, freely given, and documented consent before most data processing begins. Pre-ticked boxes and bundled consent buried in terms of service do not qualify. CCPA allows collection by default but requires a clear "Do Not Sell or Share My Personal Information" link on any webpage where California data is collected, and businesses must honor Global Privacy Control (GPC) browser signals automatically.

Definition of personal data. GDPR captures any information that can identify an individual directly or indirectly — including pseudonymized data if re-identification is reasonably possible. CCPA covers a similar range but adds explicit protection for household data and creates a heightened category of sensitive personal information (SPI) under CPRA, including Social Security numbers, financial account details, geolocation data, racial or ethnic origin, and health information.

Breach notification. GDPR requires notifying the relevant supervisory authority within 72 hours of discovering a breach that risks individuals' rights and freedoms. CCPA does not set a breach notification timeline directly—instead, it gives consumers a private right of action when their data is exposed due to inadequate security practices.

Cross-border data transfers. GDPR restricts personal data from leaving the European Economic Area unless the destination country provides adequate protection or an approved transfer mechanism is in place—such as standard contractual clauses. The EU-US Data Privacy Framework, adopted in July 2023, restored a legal pathway for transatlantic transfers, but organizations must self-certify with the US Department of Commerce to rely on it. CCPA imposes no equivalent cross-border restrictions.

How Do US Businesses Comply With Both GDPR and CCPA?

The most practical approach is a unified privacy program that addresses both frameworks simultaneously—most of the foundational work overlaps and serves both regulations at once.

Map your data first. Inventory every category of personal data your organization collects, where it comes from, what legal basis supports it under GDPR, whether it constitutes a "sale or share" under CCPA, and how long it is retained. This is not a one-time project—it needs to be updated as your data practices change.

Write one strong privacy notice. A GDPR-compliant privacy notice—specifying legal basis, retention periods, data subject rights, and supervisory authority contact—will also satisfy CCPA's disclosure requirements. One document meeting the stricter standard serves both.

Deploy a consent management platform. If your site serves EU and California users, a consent management platform that delivers geo-targeted consent flows handles both frameworks efficiently. EU visitors receive an opt-in banner. California visitors receive an opt-out mechanism. Both interactions are logged for compliance documentation.

Train your team on real scenarios. Staff who handle personal data—customer service, marketing, HR, IT & risk managers—need to know what to do when a consumer sends a data access request, when a breach occurs, and when a vendor agreement requires updating. Regulatory enforcement increasingly targets employee-level failures, not just policy gaps.

What Has Changed in Privacy Compliance in 2026?

The privacy landscape in 2026 is significantly more complex than when CCPA first took effect in 2020—US businesses now face a national patchwork of state privacy laws, not just a California-specific obligation. 

As of 2026, comprehensive consumer privacy laws are in effect across more than a dozen US states, including Virginia, Colorado, Connecticut, Texas, Montana, and Oregon. Most draw from the same consumer rights framework established by CCPA, but enforcement timelines, cure periods, and sensitive data definitions vary by state. A privacy program designed around CCPA provides a strong starting point but cannot be copied across state lines without review. 

At the federal level, comprehensive privacy efforts remain fluid. While the proposed American Privacy Rights Act (APRA) draft stalled in committee during the 118th Congress, the House Energy and Commerce Committee introduced a new federal baseline framework called the SECURE Data Act. If eventually enacted, it would establish a national privacy baseline and preempt a large portion of the state laws. US organizations should monitor its legislative tracking closely, as federal movement would require another compliance program update. 

On the EU side, the European Data Protection Board issued Guidelines 1/2024 regarding data processing based on legitimate interests under Article 6(1)(f). This framework, supported by contemporaneous rulings from the Court of Justice of the European Union (CJEU), dramatically raised the bar for documenting the mandatory three-part compliance assessment. It heavily restricted using legitimate interest as a legal basis for highly invasive tracking and behavioral profiling. Organizations relying on this basis for digital operations should review their assessments against these updated guidelines. 

Frequently Asked Questions

01 Who is not covered by GDPR? +

GDPR does not apply to individuals processing data for purely personal or household purposes—a private address book or personal social media account falls outside its scope. Organizations based entirely outside the EU that have no contact with EU residents, offer no goods or services to EU individuals and do not monitor behavior occurring within the EU are excluded. In practice, US commercial websites fall within the regulation's reach under Article 3(2) only if they intentionally target EU consumers—such as by offering localized currency, language options, or tracking user behavior to build behavioral profiles. Passive website traffic alone does not automatically trigger compliance obligations. 

02 Who is responsible for enforcing the CCPA? +

CCPA enforcement is shared between the California Attorney General and the California Privacy Protection Agency (CPPA), which became fully operational in 2023 as the first dedicated state privacy regulator in U.S. history. The CPPA has independent investigative powers, can initiate investigations without a consumer complaint, and issues administrative fines directly. Consumers also hold a limited private right of action under CCPA—specifically for data breaches caused by a business's failure to implement reasonable security measures, with statutory damages of $100 to $750 per consumer per incident.

03 Who do GDPR and CCPA apply to? +

GDPR applies to any organization—regardless of where it is headquartered—that processes personal data of individuals physically located in the European Union. CCPA applies to for-profit businesses that collect California resident data and meet at least one threshold: annual gross revenue above $25 million, data from 100,000 or more California consumers or households annually, or 50% or more of revenue derived from selling or sharing personal information. A single US company can fall under both laws simultaneously, which is the norm for any business with EU-facing digital products or services.

04 What are some examples of CCPA violations? +

Common CCPA violations include failing to display a "Do Not Sell or Share My Personal Information" link on data-collecting pages; not honoring Global Privacy Control opt-out signals from consumers' browsers; failing to respond to verified data access or deletion requests within the 45-day window; sharing consumer data with third-party advertising platforms without a valid service provider contract; and collecting personal information from consumers under 16 without opt-in consent. Sephora's 2022 settlement—$1.2 million to the California AG—involved multiple of these failures simultaneously and remains the clearest enforcement benchmark for US businesses.

05 Which is better, CCPA or GDPR? +

Neither is objectively better—they reflect different legal philosophies. GDPR is more protective: it requires opt-in consent before data collection, restricts international transfers, and carries penalties that scale to global revenue. CCPA is more permissive at baseline — businesses can collect data by default — but gives consumers meaningful control after the fact. For US businesses, the practical question is not which is better but which applies to them and how to satisfy both efficiently. Organizations that build to GDPR's stricter standard typically find CCPA compliance easier to layer on top, since GDPR's consent and documentation requirements exceed what CCPA demands.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.