GDPR vs CCPA—What US Businesses Must Know in 2026

Compare GDPR vs CCPA in 2026. Learn key differences, consent rules, penalties, compliance requirements, and new CCPA regulations for US businesses.

GDPR vs CCPA—What US Businesses Must Know in 2026

The GDPR and the CCPA are the two most consequential data privacy laws affecting US businesses today. The General Data Protection Regulation governs how any organization worldwide handles the personal data of EU residents. The California Consumer Privacy Act—expanded significantly by the California Privacy Rights Act—sets the standard for how businesses treat the data of California residents. Together, these two laws shape compliance obligations for millions of US companies, whether they serve EU customers, operate in California, or both. This guide breaks down exactly how they differ, what has changed in 2026, and what your business needs to do about it.

What Is the GDPR and Does It Apply to Your US Business?

The GDPR applies to any organization worldwide that processes the personal data of EU residents — including US businesses with no physical presence in Europe. It came into force on May 25, 2018, replacing the EU's outdated 1995 Data Protection Directive, and is widely regarded as the world's strictest data privacy law.

If your US business sells to EU customers, runs analytics on EU website visitors, or sends marketing emails to EU contacts, the GDPR applies to you. EU residents hold defined rights: access to their data, erasure, rectification, data portability, and the right to object to certain processing. Organizations must respond to these requests without undue delay and at most within one month, with extensions up to two additional months permitted for complex cases. 

Enforcement is anything but symbolic. According to industry tracking data, cumulative GDPR fines now exceed €7.1 billion since the law took effect, backed by significant regulatory activity over the last 12 months. The largest single fine—€1.2 billion against Meta in 2023 for unlawful data transfers to the US—remains the record, but finance, healthcare, and telecoms are now firmly in scope alongside Big Tech. 

What Is the CCPA and Which US Businesses Must Comply?

The CCPA is the most comprehensive US state-level privacy law, applying to for-profit businesses connected to California that meet at least one threshold: annual gross revenues above $25 million; buying, selling, or sharing the personal data of 100,000 or more consumers or households annually; or deriving 50% or more of annual revenue from selling or sharing consumer personal data. You must comply regardless of where your company is headquartered. 

California residents hold the right to know what data is collected and why, the right to delete it, the right to opt out of its sale or sharing, the right to correct inaccurate information, and the right to non-discrimination for exercising any of these rights. 

Oversight sits with the California Privacy Protection Agency (CalPrivacy), which is actively enforcing. The agency and the California Attorney General have significantly ramped up enforcement actions, targeting companies for faulty opt-out mechanisms, non-compliant privacy notices, and the unlawful sale or sharing of consumer location and behavioral data to third-party data brokers without valid consent. 

The Key Differences Between GDPR and CCPA That Actually Matter

The most important difference is the consent model. The GDPR requires opt-in consent: users must actively agree before most personal data is collected. The CCPA defaults to opt-out: businesses can collect and use data unless consumers specifically object. A GDPR-compliant consent banner does not automatically satisfy CCPA, and vice versa.

Scope differs too. The GDPR covers virtually any organization globally that processes EU resident data, including nonprofits. The CCPA applies only to qualifying for-profit businesses connected to California. On penalties, GDPR fines reach up to €20 million or 4% of global annual revenue, whichever is higher. Statutory CCPA civil penalties are set at $2,500 per unintentional violation and $7,500 per intentional violation, alongside a private right of action for data breach victims that allows for statutory damages between $100 and $750 per consumer per incident.

GDPR vs CCPA Comparison Table

Feature

GDPR

CCPA

Jurisdiction

EU & EEA (global reach)

California, USA

Effective Date

May 2018

January 2020

Consent Model

Opt-in (explicit)

Opt-out (implicit)

Who It Covers

Any org processing EU data

For-profit CA businesses

Right to Access

Yes

Yes

Right to Delete

Yes

Yes

Data Portability

Yes

Yes

Non-Discrimination

Not explicitly stated

Yes

Max Fine

€20M or 4% global revenue

$7,500 per intentional violation

Enforcement Body

Data Protection Authorities

California AG & CPPA

Data Breach Notice

72 hours

Reasonable time

Which Privacy Law Is Stricter?

The GDPR is stricter — its opt-in consent standard, broader global reach, and significantly higher fines make it the more demanding framework overall. The CCPA is stronger in one specific area: the explicit right to non-discrimination for exercising privacy rights has no direct GDPR equivalent, and the CCPA's private right of action for data breaches creates litigation exposure the GDPR enforcement model does not replicate.

The practical takeaway for US businesses: GDPR compliance gets you roughly 80% of the way to CCPA compliance. The remaining gap—opt-out mechanisms, specific CCPA disclosure language, and Global Privacy Control signal requirements—requires targeted, independent attention.

What Changed in 2026: The New CCPA Rules US Businesses Must Know

As of January 1, 2026, the CCPA entered its most demanding phase yet—and this is the update most compliance programs have not caught up with. Navigating these regulatory updates heavily relies on a qualified risk manager whose core responsibilities include aligning legal mandates with company operations.  Three new categories of obligation are now in force following CalPrivacy's September 2025 rulemaking.

Mandatory risk assessments. Businesses must conduct formal privacy risk assessments before engaging in processing that presents significant risk to consumers—including sensitive data, large-scale profiling, and targeted advertising. For processing already underway, initial assessments must be completed by December 31, 2027, with attestations to CalPrivacy by April 1, 2028.

Automated decision-making technology (ADMT) obligations. Businesses using automated systems to make significant decisions—employment, credit and housing—must provide a prominent pre-use notice and give consumers the right to opt out. Existing deployments have until January 1, 2027; new deployments are subject immediately.

Mandatory cybersecurity audits. Qualifying businesses must now conduct independent annual cybersecurity audits. This shifts CCPA compliance from transparency-based to accountability-based — having a privacy policy is no longer enough.

Understanding these rules is the right starting point. Knowing how to build the systems that satisfy them is a different challenge. Our [Data Privacy and Governance: GDPR, CCPA, and Data Ethics] course gives compliance professionals and business owners the practical framework to implement both laws correctly — not just summarize them.

What Your Business Actually Needs to Do

These are the five actions that matter most right now.

Audit your data. Know exactly what personal data you collect, where it is stored, who has access, and why. Both laws require this level of transparency — and neither allows you to claim ignorance about your own data practices.

Update your privacy policy. It must state what categories of data you collect, the purposes of collection, retention periods, whether you sell or share data, and how consumers can exercise their rights. The 2026 CCPA updates require more specific disclosures than the 2020 version required.

Make your opt-out mechanism actually work. The Tractor Supply fine came from a "Do Not Sell" link that did not stop data sales. Your website must also honor Global Privacy Control (GPC) browser signals, which California treats as a valid opt-out request.

Build a consumer rights response process. Both laws require responses to access, deletion, correction, and portability requests — typically within 30 to 45 days. That process must be operationally real.

Review your vendor contracts. The CCPA's 2026 enforcement has specifically targeted inadequate service provider agreements. If your contracts with analytics platforms or advertising tools do not include required CCPA or GDPR clauses, the liability falls on you. Mitigating this kind of vendor exposure requires the sharp eye of a corporate risk manager possessing the key skills to audit third-party legal threats. 

If you are responsible for privacy compliance at your organization, structured training is the most reliable way to reduce risk and build team confidence. Our [Data Privacy and Governance: GDPR, CCPA, and Data Ethics] course walks teams through real situations and the correct responses in a format built for working professionals.

The Future of US Data Privacy

Approximately 20 US states now have comprehensive consumer privacy laws in effect—Virginia, Colorado, Texas, Indiana, Kentucky, and Rhode Island among them. No new state passed a comprehensive law in 2025, the first such gap since 2020, but AI regulation and children's data protections remain active areas. You can track every active law through the IAPP US State Privacy Legislation Tracker.

A federal privacy law remains unlikely in the near term. States continue to fill the enforcement gap. For US businesses operating across multiple states, building a scalable privacy program now is far more cost-effective than retrofitting compliance law by law.

 

Frequently Asked Questions

01 Does GDPR apply to US companies? +

Yes, if your business serves EU residents. The GDPR applies based on who your users are, not where your company is registered. If you collect data from EU residents through website analytics, marketing emails, or e-commerce sales to Europe, the GDPR likely applies. EU regulators have limited direct enforcement authority over purely domestic US companies, but GDPR compliance is increasingly required by European enterprise clients as a contractual condition — making it both a legal and commercial risk to ignore.

02 Is the CCPA still in effect in 2026, and what has changed? +

The CCPA is fully in effect and more demanding than at any point since its 2020 launch. Three major new obligations took effect January 1, 2026: mandatory risk assessments for high-risk data processing, disclosure and opt-out requirements for automated decision-making technology, and mandatory annual cybersecurity audits. CalPrivacy is actively enforcing — the $12.75 million GM settlement in May 2026 is the largest CCPA fine ever issued, and the agency has confirmed hundreds of active investigations running at any given time.

03 What is the biggest practical difference between GDPR and CCPA? +

The consent model. GDPR requires opt-in — users must actively agree before data is collected. CCPA defaults to opt-out — you can collect data unless consumers object. This means the two laws require different technical implementations. A GDPR consent banner does not satisfy CCPA requirements. California also requires businesses to honor browser-based Global Privacy Control opt-out signals — a technical obligation many companies are still not meeting. Both laws carry distinct disclosure language requirements that a single privacy policy cannot satisfy.

04 Do I need to comply with both GDPR and CCPA? +

Yes, if your business meets both sets of thresholds. A US company with revenues above $26.6 million, California customers, and EU users must comply with both simultaneously. Roughly 80% of GDPR compliance translates directly to CCPA compliance — both require privacy policies, consumer rights processes, vendor data agreements, and reasonable security measures. The remaining gap covers consent model differences, specific CCPA disclosure language, Global Privacy Control obligations, and the 2026 ADMT and risk assessment requirements, which need targeted, framework-specific attention.

05 What happens if my business ignores CCPA compliance in 2026? +

Enforcement is no longer theoretical. The CPPA and California Attorney General maintain active investigative sweeps across multiple industries, frequently focusing on mobile apps, retail platforms, and connected tech. Civil penalties reach $7,500 per intentional violation — and across millions of consumer records, aggregate exposure can scale rapidly. Beyond fines, the CCPA's private right of action means consumers can sue independently following a data breach tied to inadequate security, with statutory damages of up to $750 per consumer per incident. Regulatory authorities have stated publicly that fines must not become a routine cost of doing business, and injunctive requirements in settlements are often more operationally disruptive than the financial penalties themselves.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.