The General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) are the two most consequential data privacy laws affecting US businesses today. GDPR governs how organizations handle personal data of EU residents. CCPA gives California consumers the right to know, access, and limit how their data is used. Despite different origins, both laws impose real compliance obligations on American companies — and ignoring either carries significant legal and financial risk. This guide breaks down how each law works, where they differ, and what your organization needs to do to comply with both in 2026.
What Is GDPR and Which US Companies Does It Apply To?
GDPR applies to any organization that collects or processes personal data from individuals in the European Union—regardless of where that business is located. That scope catches most US companies off guard.
The regulation came into force in May 2018 and replaced a fragmented set of national data protection laws across EU member states. Personal data under GDPR is defined broadly: names, email addresses, IP addresses, location data, cookie identifiers, and any information that can directly or indirectly identify a living individual. If your website, app, or e-commerce store attracts EU users and collects any of that data, GDPR applies to you.
Every data collection activity must have a lawful basis—consent, contractual necessity, legal obligation, legitimate interest, vital interests, or public task. Data cannot be collected simply because it might be useful later.
Key obligations include:
-
Obtaining explicit consent before processing where consent is the legal basis
-
Publishing a clear privacy notice explaining what data is collected, why, and how long it is retained
-
Responding to individual requests to access, correct, port, or delete personal data
-
Reporting qualifying data breaches to regulators within 72 hours of discovery
Penalties reach up to €20 million or 4% of annual global turnover—whichever is higher. In 2023, Meta was fined €1.2 billion by Ireland's Data Protection Commission for unlawful transfers of EU user data to the United States—the largest GDPR penalty on record. That figure alone illustrates the enforcement risk US companies now face.
What Is CCPA and Does It Apply to Your Business?
CCPA applies to for-profit businesses that collect data from California residents and meet at least one specific revenue or data-volume threshold—not every business that touches California user data.
The law took effect in January 2020 and was strengthened significantly by the California Privacy Rights Act (CPRA) in January 2023. The CPRA established the California Privacy Protection Agency (CPPA)—the first dedicated state privacy regulator in US history—and expanded consumer rights beyond the original CCPA framework.
A business falls under CCPA if it meets any one of these thresholds:
-
Annual gross revenue exceeding $25 million
-
Annual purchase, sale, or receipt of personal information from 100,000 or more California consumers or households
-
Deriving 50% or more of annual revenue from selling or sharing personal information
California residents can request to know what data is collected, demand deletion, opt out of data sales or sharing, correct inaccurate data, and limit the use of sensitive personal information—a right added under the CPRA. Businesses cannot retaliate against consumers who exercise any of these rights.
Civil penalties are $2,500 per unintentional violation and $7,500 per intentional violation—calculated per consumer per incident. In 2022, Sephora became the first company to settle a CCPA enforcement action, paying $1.2 million for failing to disclose data sales and ignoring opt-out signals. CCPA also provides consumers a private right of action when unencrypted personal data is exposed due to a business's failure to maintain reasonable security practices.
Where Do GDPR and CCPA Fundamentally Differ?

The core difference comes down to consent philosophy: GDPR requires opt-in before data collection; CCPA allows data collection by default and gives consumers the right to opt out after the fact.
That distinction shapes everything else about how each law operates. Here is where the two frameworks diverge most significantly.
Consent model. GDPR requires affirmative, freely given, and documented consent before most data processing begins. Pre-ticked boxes and bundled consent buried in terms of service do not qualify. CCPA allows collection by default but requires a clear "Do Not Sell or Share My Personal Information" link on any webpage where California data is collected, and businesses must honor Global Privacy Control (GPC) browser signals automatically.
Definition of personal data. GDPR captures any information that can identify an individual directly or indirectly — including pseudonymized data if re-identification is reasonably possible. CCPA covers a similar range but adds explicit protection for household data and creates a heightened category of sensitive personal information (SPI) under CPRA, including Social Security numbers, financial account details, geolocation data, racial or ethnic origin, and health information.
Breach notification. GDPR requires notifying the relevant supervisory authority within 72 hours of discovering a breach that risks individuals' rights and freedoms. CCPA does not set a breach notification timeline directly—instead, it gives consumers a private right of action when their data is exposed due to inadequate security practices.
Cross-border data transfers. GDPR restricts personal data from leaving the European Economic Area unless the destination country provides adequate protection or an approved transfer mechanism is in place—such as standard contractual clauses. The EU-US Data Privacy Framework, adopted in July 2023, restored a legal pathway for transatlantic transfers, but organizations must self-certify with the US Department of Commerce to rely on it. CCPA imposes no equivalent cross-border restrictions.
How Do US Businesses Comply With Both GDPR and CCPA?

The most practical approach is a unified privacy program that addresses both frameworks simultaneously—most of the foundational work overlaps and serves both regulations at once.
Map your data first. Inventory every category of personal data your organization collects, where it comes from, what legal basis supports it under GDPR, whether it constitutes a "sale or share" under CCPA, and how long it is retained. This is not a one-time project—it needs to be updated as your data practices change.
Write one strong privacy notice. A GDPR-compliant privacy notice—specifying legal basis, retention periods, data subject rights, and supervisory authority contact—will also satisfy CCPA's disclosure requirements. One document meeting the stricter standard serves both.
Deploy a consent management platform. If your site serves EU and California users, a consent management platform that delivers geo-targeted consent flows handles both frameworks efficiently. EU visitors receive an opt-in banner. California visitors receive an opt-out mechanism. Both interactions are logged for compliance documentation.
Train your team on real scenarios. Staff who handle personal data—customer service, marketing, HR, IT & risk managers—need to know what to do when a consumer sends a data access request, when a breach occurs, and when a vendor agreement requires updating. Regulatory enforcement increasingly targets employee-level failures, not just policy gaps.
Featured Course
Data Privacy and Governance: GDPR, CCPA and Data Ethics
If you are responsible for privacy governance in your organization, structured and up-to-date training is the most reliable way to stay ahead of these changes. Our Data Privacy And Governance GDPR CCPA And Data Ethics course reflects current law across both frameworks and gives practitioners working knowledge of how to apply them—not just what they say.
What Has Changed in Privacy Compliance in 2026?
The privacy landscape in 2026 is significantly more complex than when CCPA first took effect in 2020—US businesses now face a national patchwork of state privacy laws, not just a California-specific obligation.
As of 2026, comprehensive consumer privacy laws are in effect across more than a dozen US states, including Virginia, Colorado, Connecticut, Texas, Montana, and Oregon. Most draw from the same consumer rights framework established by CCPA, but enforcement timelines, cure periods, and sensitive data definitions vary by state. A privacy program designed around CCPA provides a strong starting point but cannot be copied across state lines without review.
At the federal level, comprehensive privacy efforts remain fluid. While the proposed American Privacy Rights Act (APRA) draft stalled in committee during the 118th Congress, the House Energy and Commerce Committee introduced a new federal baseline framework called the SECURE Data Act. If eventually enacted, it would establish a national privacy baseline and preempt a large portion of the state laws. US organizations should monitor its legislative tracking closely, as federal movement would require another compliance program update.
On the EU side, the European Data Protection Board issued Guidelines 1/2024 regarding data processing based on legitimate interests under Article 6(1)(f). This framework, supported by contemporaneous rulings from the Court of Justice of the European Union (CJEU), dramatically raised the bar for documenting the mandatory three-part compliance assessment. It heavily restricted using legitimate interest as a legal basis for highly invasive tracking and behavioral profiling. Organizations relying on this basis for digital operations should review their assessments against these updated guidelines.