Data Privacy and Governance: GDPR, CCPA and Data Ethics
Avoid becoming the next enforcement headline. Our Data Privacy and Governance: GDPR, CCPA and Data Ethics course teaches practical compliance strategies that reduce regulatory risk.
GDPR and CCPA are the two most influential data privacy laws shaping how organizations collect, use, and protect personal information today. GDPR governs how businesses handle the personal data of people in the European Union. CCPA—now strengthened by the California Privacy Rights Act (CPRA)—gives California residents control over how their information is collected and sold. For US businesses operating online, understanding the GDPR vs CCPA differences is no longer a legal team issue alone. It is an operational requirement with direct financial consequences for organizations at every level.
The General Data Protection Regulation (GDPR) came into force in May 2018 and is widely recognized as the most comprehensive data privacy law in the world. Introduced by the European Union, it establishes strict rules for how organizations collect, process, store, and transfer personal data—and it applies globallyto any organization targeting or monitoring individuals who are physically located within the EU, regardless of the business's physical headquarters.
The main purpose of GDPR is to give individuals greater control over their personal data while holding organizations accountable for how that data is handled. Any US company that offers goods or services to EU residents or that monitors the behavior of individuals within the EU must comply—regardless of where the company is headquartered.
GDPR is built on seven core principles: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. These principles govern every data processing decision an organization makes, from marketing emails to analytics platforms.
The regulation also imposes strict requirements around the legal basis for data processing. Before collecting personal information, organizations must establish one of six legal bases — including consent, legitimate interest, or contractual necessity. This is one of the most significant ways GDPR differs from US privacy law.
The California Consumer Privacy Act (CCPA) became enforceable in January 2020 and has since been significantly expanded by the California Privacy Rights Act (CPRA), which took full effect in January 2023. Together, they form the strongest consumer privacy framework in the United States.
The CCPA gives California residents the right to know what personal data businesses collect about them, why it is collected, and whether it is sold or shared with third parties. Consumers can request deletion of their data, opt out of data sales, and cannot be discriminated against for exercising their privacy rights.
CCPA applies to for-profit businesses that do business in California and meet at least one of the following thresholds (as adjusted by California's Consumer Price Index):
Annual gross revenue exceeding $26,625,000
Buy, sell, or share the personal information of 100,000 or more California consumers or households annually
Derive 50% or more of annual revenue from selling or sharing consumers' personal information
A business does not need to be based in California to fall under this law. An online retailer headquartered in Texas that sells to California residents and meets any one of the thresholds above must comply.
The California Privacy Rights Act (CPRA) is not a separate law—it amended and expanded the CCPA. The California Privacy Protection Agency (CPPA), established by the CPRA, is now the dedicated enforcement body operating alongside the California Attorney General. Key changes the CPRA introduced include:
A new right to limit the use of sensitive personal information (health data, precise geolocation, financial details)
A new right to correct inaccurate personal information
Expanded opt-out rights to cover sharing of data — not just sales
Stricter data retention requirements
Mandatory risk assessments and cybersecurity audits for high-risk processing activities
Following extensive public debate and formal draft reviews, the CPPA finalized comprehensive rules addressing complex processing ecosystems. These highly anticipated regulations introduce stringent frameworks for mandatory corporate cybersecurity audits, structured risk assessments for automated decision-making technology (ADMT), and expanded operational obligations for registered data brokers.
Enforcement under both laws has moved well beyond symbolic penalties. US businesses operating across borders are now facing real financial consequences.
On the GDPR side, cumulative fines have exceeded several billion euros since enforcement began in 2018 (according to ongoing tracking data compiled by independent legal networks like the CMS GDPR Enforcement Tracker).Regulators continue to aggressively penalize tech companies, with the largest single GDPR fine on record remaining the €1.2 billion penalty levied against Meta in 2023 for unauthorized EU-US data transfers. Furthermore, enforcement by European Data Protection Authorities routinely targets cross-border compliance failures across finance, healthcare, retail, and technology spaces.
CCPA enforcement is escalating just as quickly. In February 2026, the California attorney general announced a historic $2.75 million settlement against The Walt Disney Company to resolve allegations that its streaming services failed to honor consumer opt-out choices consistently across multiple platforms and devices. This stands as the largest civil penalty secured under the CCPA to date. In September 2025, the California Privacy Protection Agency fined Tractor Supply Company $1.35 million for inadequate privacy notices and broken opt-out mechanisms. In July 2025, a $1.55 million settlement with Healthline resolved violations around third-party data sharing and opt-out failures.
The vast majority of high-profile CCPA enforcement actions have centrally featured a failure to honor the consumer's right to opt out or recognize global privacy signals. While regulators also look closely at data processing agreements and workplace notice compliance, businesses that have failed to implement robust, fully tested consumer opt-out mechanisms remain the primary, most visible targets for significant financial penalties.
Avoid becoming the next enforcement headline. Our Data Privacy and Governance: GDPR, CCPA and Data Ethics course teaches practical compliance strategies that reduce regulatory risk.

GDPR applies globally. Any organization that processes personal data of EU residents—regardless of where it is based—must comply. US companies serving European customers are directly in scope.
CCPA applies to for-profit businesses meeting the thresholds above that do business in California. Geographic location of the business does not matter—what matters is whether California residents' data is being processed.
This is the most fundamental operational difference between the two laws.
GDPR requires explicit opt-in consent for many categories of data processing — particularly for marketing, tracking, and sensitive personal data. Businesses must obtain clear, specific permission before collecting or using data for these purposes. Silence or pre-ticked boxes do not constitute consent under GDPR.
CCPA follows an opt-out model. Businesses may collect and use personal information by default but must give consumers a clear, easy mechanism to opt out of the sale or sharing of their data. The "Do Not Sell or Share My Personal Information" link is the most visible expression of this requirement.
Both laws grant individuals rights over their personal data, but GDPR's framework is broader.
GDPR rights include:
Right to access personal data
Right to rectify inaccurate data
Right to erasure ("right to be forgotten")
Right to restrict processing
Right to data portability
Right to object to processing
Rights related to automated decision-making
CCPA/CPRA rights include:
Right to know what data is collected and how it is used
Right to delete personal information
Right to opt out of sale or sharing
Right to correct inaccurate information (added by CPRA)
Right to limit use of sensitive personal information (added by CPRA)
Right to non-discrimination for exercising privacy rights
|
GDPR |
CCPA/CPRA |
|
|
Maximum fine |
€20M or 4% of global annual revenue |
$7,988 per intentional violation (2025 CPI-adjusted) |
|
Enforcement body |
EU Data Protection Authorities |
California Privacy Protection Agency + California AG |
|
Private right of action |
Limited |
Yes — for data breaches |
GDPR fines are substantially higher in absolute terms, but CCPA's private right of action for data breaches opens businesses to class-action litigation that can far exceed per-violation penalties.
GDPR requires organizations to identify and document a legal basis for every data processing activity before it begins. Options include consent, contract, legal obligation, legitimate interests, vital interests, or public task.
CCPA does not require organizations to justify a legal basis for processing. The focus is on transparency and consumer choice — businesses must disclose what they collect and why, and honor opt-out requests.
GDPR strictly governs cross-border data transfers. Organizations transferring personal data outside the European Economic Area must use approved mechanisms: Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or rely on an EU adequacy decision (such as the EU-US Data Privacy Framework).
CCPA places no general restrictions on international transfers, though the 2025 risk assessment regulations now apply to certain cross-border transfers that present significant privacy risk.
|
Feature |
GDPR |
CCPA/CPRA |
|
Geographic Scope |
Global (EU resident data) |
California businesses meeting thresholds |
|
Consent Model |
Opt-in required |
Opt-out of sale/sharing |
|
Enforcement Authority |
EU Data Protection Authorities |
CPPA + California Attorney General |
|
Maximum Penalties |
€20M or 4% of global revenue |
$7,988 per intentional violation |
|
Private Right of Action |
Limited |
Yes, for data breaches |
|
Legal Basis Required |
Yes — six lawful bases |
No |
|
Data Transfers |
Strict international restrictions |
Limited restrictions |
|
Sensitive Data Rules |
Detailed specific categories |
Right to limit use (added by CPRA) |

US businesses face a more complex privacy landscape in 2026 than at any previous point. GDPR applies the moment a US company markets to or processes data from European users. CCPA applies when a US company crosses the California thresholds — and as of early 2026, approximately 20 US states have enacted comprehensive consumer privacy laws, with Indiana, Kentucky, and Rhode Island going live on January 1, 2026.
Common operational challenges include managing different consent mechanisms for different user populations, aligning privacy policies across jurisdictions, responding to consumer data requests within legal deadlines, and maintaining working opt-out mechanisms that regulators will test.
Developing internal expertise in privacy governance is now a core business requirement—not a compliance checkbox. Many organizations are investing in structured training programs that cover both GDPR and CCPA frameworks, data ethics, and practical compliance workflows, such as Data Privacy And Governance GDPR CCPA And Data Ethics, which equip professionals to manage real-world privacy obligations across jurisdictions.
Conduct a Data Inventory Identify every category of personal data your organization collects, where it is stored, how long it is retained, and who it is shared with. This is the foundation of compliance under both laws. You cannot protect data you cannot locate.
Update Privacy Policies and Notices Privacy policies must clearly explain what data is collected, why, how long it is kept, and how consumers can exercise their rights. For CCPA, a "Do Not Sell or Share My Personal Information" mechanism must be visible and functional. For GDPR, notices must be presented at or before the point of data collection.
Implement and Test Consent Management Systems Consent management platforms help businesses capture opt-in signals for GDPR and manage opt-out requests under CCPA. Critically, regulators now test whether opt-out mechanisms actually work. A link that does not function is treated the same as having no mechanism at all.
Strengthen Data Security Practices Both laws hold organizations responsible for protecting the data they collect. Encryption, access controls, breach response procedures, and regular security audits are all required under GDPR. Under CPRA, cybersecurity audit obligations are now mandatory for certain businesses.
Train Teams Across the Organization Privacy compliance is not a legal function alone. Marketing, product, HR, and customer service teams all handle personal data. Structured training programs such as Data Privacy and Governance, GDPR, CCPA, and Data Ethics help teams across every function understand their obligations and apply them correctly under real workplace conditions.
Privacy regulation is not slowing down — it is accelerating. GDPR enforcement crossed €7.1 billion in cumulative fines, CCPA just produced its largest settlement ever, and 20 US states now have active privacy laws. The gap between businesses with structured compliance programs and those still treating privacy as a checkbox is closing fast — and regulators are increasingly focused on it.
Organizations that understand both GDPR and CCPA — their differences, their overlapping requirements, and where they are heading — will spend less time reacting to enforcement actions and more time building the kind of data trust that customers increasingly expect.