The GDPR and the CCPA are the two most consequential data privacy laws affecting US businesses today. The General Data Protection Regulation governs how any organization worldwide handles the personal data of EU residents. The California Consumer Privacy Act—expanded significantly by the California Privacy Rights Act—sets the standard for how businesses treat the data of California residents. Together, these two laws shape compliance obligations for millions of US companies, whether they serve EU customers, operate in California, or both. This guide breaks down exactly how they differ, what has changed in 2026, and what your business needs to do about it.
What Is the GDPR and Does It Apply to Your US Business?
The GDPR applies to any organization worldwide that processes the personal data of EU residents — including US businesses with no physical presence in Europe. It came into force on May 25, 2018, replacing the EU's outdated 1995 Data Protection Directive, and is widely regarded as the world's strictest data privacy law.
If your US business sells to EU customers, runs analytics on EU website visitors, or sends marketing emails to EU contacts, the GDPR applies to you. EU residents hold defined rights: access to their data, erasure, rectification, data portability, and the right to object to certain processing. Organizations must respond to these requests without undue delay and at most within one month, with extensions up to two additional months permitted for complex cases.
Enforcement is anything but symbolic. According to industry tracking data, cumulative GDPR fines now exceed €7.1 billion since the law took effect, backed by significant regulatory activity over the last 12 months. The largest single fine—€1.2 billion against Meta in 2023 for unlawful data transfers to the US—remains the record, but finance, healthcare, and telecoms are now firmly in scope alongside Big Tech.
What Is the CCPA and Which US Businesses Must Comply?
The CCPA is the most comprehensive US state-level privacy law, applying to for-profit businesses connected to California that meet at least one threshold: annual gross revenues above $25 million; buying, selling, or sharing the personal data of 100,000 or more consumers or households annually; or deriving 50% or more of annual revenue from selling or sharing consumer personal data. You must comply regardless of where your company is headquartered.
California residents hold the right to know what data is collected and why, the right to delete it, the right to opt out of its sale or sharing, the right to correct inaccurate information, and the right to non-discrimination for exercising any of these rights.
Oversight sits with the California Privacy Protection Agency (CalPrivacy), which is actively enforcing. The agency and the California Attorney General have significantly ramped up enforcement actions, targeting companies for faulty opt-out mechanisms, non-compliant privacy notices, and the unlawful sale or sharing of consumer location and behavioral data to third-party data brokers without valid consent.
The Key Differences Between GDPR and CCPA That Actually Matter

The most important difference is the consent model. The GDPR requires opt-in consent: users must actively agree before most personal data is collected. The CCPA defaults to opt-out: businesses can collect and use data unless consumers specifically object. A GDPR-compliant consent banner does not automatically satisfy CCPA, and vice versa.
Scope differs too. The GDPR covers virtually any organization globally that processes EU resident data, including nonprofits. The CCPA applies only to qualifying for-profit businesses connected to California. On penalties, GDPR fines reach up to €20 million or 4% of global annual revenue, whichever is higher. Statutory CCPA civil penalties are set at $2,500 per unintentional violation and $7,500 per intentional violation, alongside a private right of action for data breach victims that allows for statutory damages between $100 and $750 per consumer per incident.
Featured Course
Data Privacy and Governance: GDPR, CCPA, and Data Ethics
If you need to navigate GDPR and CCPA requirements with confidence, our Data Privacy and Governance: GDPR, CCPA, and Data Ethics course explains key differences, compliance obligations, and practical implementation strategies.
GDPR vs CCPA Comparison Table
|
Feature
|
GDPR
|
CCPA
|
|
Jurisdiction
|
EU & EEA (global reach)
|
California, USA
|
|
Effective Date
|
May 2018
|
January 2020
|
|
Consent Model
|
Opt-in (explicit)
|
Opt-out (implicit)
|
|
Who It Covers
|
Any org processing EU data
|
For-profit CA businesses
|
|
Right to Access
|
Yes
|
Yes
|
|
Right to Delete
|
Yes
|
Yes
|
|
Data Portability
|
Yes
|
Yes
|
|
Non-Discrimination
|
Not explicitly stated
|
Yes
|
|
Max Fine
|
€20M or 4% global revenue
|
$7,500 per intentional violation
|
|
Enforcement Body
|
Data Protection Authorities
|
California AG & CPPA
|
|
Data Breach Notice
|
72 hours
|
Reasonable time
|
Which Privacy Law Is Stricter?
The GDPR is stricter — its opt-in consent standard, broader global reach, and significantly higher fines make it the more demanding framework overall. The CCPA is stronger in one specific area: the explicit right to non-discrimination for exercising privacy rights has no direct GDPR equivalent, and the CCPA's private right of action for data breaches creates litigation exposure the GDPR enforcement model does not replicate.
The practical takeaway for US businesses: GDPR compliance gets you roughly 80% of the way to CCPA compliance. The remaining gap—opt-out mechanisms, specific CCPA disclosure language, and Global Privacy Control signal requirements—requires targeted, independent attention.
What Changed in 2026: The New CCPA Rules US Businesses Must Know
As of January 1, 2026, the CCPA entered its most demanding phase yet—and this is the update most compliance programs have not caught up with. Navigating these regulatory updates heavily relies on a qualified risk manager whose core responsibilities include aligning legal mandates with company operations. Three new categories of obligation are now in force following CalPrivacy's September 2025 rulemaking.
Mandatory risk assessments. Businesses must conduct formal privacy risk assessments before engaging in processing that presents significant risk to consumers—including sensitive data, large-scale profiling, and targeted advertising. For processing already underway, initial assessments must be completed by December 31, 2027, with attestations to CalPrivacy by April 1, 2028.
Automated decision-making technology (ADMT) obligations. Businesses using automated systems to make significant decisions—employment, credit and housing—must provide a prominent pre-use notice and give consumers the right to opt out. Existing deployments have until January 1, 2027; new deployments are subject immediately.
Mandatory cybersecurity audits. Qualifying businesses must now conduct independent annual cybersecurity audits. This shifts CCPA compliance from transparency-based to accountability-based — having a privacy policy is no longer enough.
Understanding these rules is the right starting point. Knowing how to build the systems that satisfy them is a different challenge. Our [Data Privacy and Governance: GDPR, CCPA, and Data Ethics] course gives compliance professionals and business owners the practical framework to implement both laws correctly — not just summarize them.
What Your Business Actually Needs to Do

These are the five actions that matter most right now.
Audit your data. Know exactly what personal data you collect, where it is stored, who has access, and why. Both laws require this level of transparency — and neither allows you to claim ignorance about your own data practices.
Update your privacy policy. It must state what categories of data you collect, the purposes of collection, retention periods, whether you sell or share data, and how consumers can exercise their rights. The 2026 CCPA updates require more specific disclosures than the 2020 version required.
Make your opt-out mechanism actually work. The Tractor Supply fine came from a "Do Not Sell" link that did not stop data sales. Your website must also honor Global Privacy Control (GPC) browser signals, which California treats as a valid opt-out request.
Build a consumer rights response process. Both laws require responses to access, deletion, correction, and portability requests — typically within 30 to 45 days. That process must be operationally real.
Review your vendor contracts. The CCPA's 2026 enforcement has specifically targeted inadequate service provider agreements. If your contracts with analytics platforms or advertising tools do not include required CCPA or GDPR clauses, the liability falls on you. Mitigating this kind of vendor exposure requires the sharp eye of a corporate risk manager possessing the key skills to audit third-party legal threats.
If you are responsible for privacy compliance at your organization, structured training is the most reliable way to reduce risk and build team confidence. Our [Data Privacy and Governance: GDPR, CCPA, and Data Ethics] course walks teams through real situations and the correct responses in a format built for working professionals.
The Future of US Data Privacy
Approximately 20 US states now have comprehensive consumer privacy laws in effect—Virginia, Colorado, Texas, Indiana, Kentucky, and Rhode Island among them. No new state passed a comprehensive law in 2025, the first such gap since 2020, but AI regulation and children's data protections remain active areas. You can track every active law through the IAPP US State Privacy Legislation Tracker.
A federal privacy law remains unlikely in the near term. States continue to fill the enforcement gap. For US businesses operating across multiple states, building a scalable privacy program now is far more cost-effective than retrofitting compliance law by law.